Debug
Debug has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Debug has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nguyen Xuan Chien. Debug is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.4.10.
CVE-2024-24798Debug <= 1.10 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Debug
Author
SoniNow
Debug can help you to find errors in your wordpress website via editing wp-config.php file. you may enable error reporting by debug plugin. enable email notification on any run time bug in wordpress CMS/website. A brief Debug Ordered list: Debug in wordpress rewrite wp-config.php file via error_log function in php. if you don’t have file write permission. so don’t use this plugin. keep backup your wp-config file before save plugin setting. How to contact the support / development team of our Debug plugin You can contact us through, https://soninow.com/contact
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C