atec Debug
atec Debug has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 3 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 2 high. 2025 was the busiest year with 3 disclosures.
The most common weakness is Absolute Path Traversal, behind 2 of the records (67%). Other recurring categories include Code Injection.
Every one of the 3 issues recorded for atec Debug has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Jonas Benjamin Friedli. atec Debug is installed on roughly 60 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-9518atec Debug <= 1.2.22 - Authenticated (Administrator+) Arbitrary File Deletion
Read the full analysisVulnerability Records

atec Debug
Author
docjojo
atec Debug is a lightweight developer toolbox to help debug your WordPress site. Features include: * View /wp-content/debug.log directly from the admin bar * Toggle WP constants like WP_DEBUG, WP_DEBUG_LOG, SAVEQUERIES, and WP_AUTO_UPDATE_CORE * View and trigger WordPress cron jobs * Parse and edit wp-config.php values like WP_MEMORY_LIMIT * Show all database queries (when SAVEQUERIES is enabled) * List all included PHP files * Read and parse the /wp-config.php file. This plugin is ideal for development and debugging in real-time, without editing files manually. Specifications Reads and parses wp-config.php and debug.log Third-Party Services Integrity check Once, when activating the plugin, an integrity check is requested from our server – if you give your permission. Source: https://atecplugins.com/ Privacy policy: https://atecplugins.com/privacy-policy/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C