ElasticPress Debugging Add-On

ElasticPress Debugging Add-On has one disclosed vulnerability in the WordSec catalog, all reported in 2022; it is fixed as of September 2026. Their average CVSS score is 7.2, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for ElasticPress Debugging Add-On has a vendor fix available, so running the current release closes it.

ElasticPress Debugging Add-On is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSHigh
7.2/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all ElasticPress Debugging Add-On vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.2

Debug Bar ElasticPress <= 2.1.0 - Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Plugin Profile
Latestv4.0.0

ElasticPress Debugging Add-On

10up

Author

10up

5.0(2)
100/100
Last Updated
2026-05-05 (4mo ago)
Active Installs
800+
Downloads
9,557,442
Requires WP
5.6+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2016-01-20 (11y ago)

Allows you to examine every ElasticPress query running on any given request by adding an ElasticPress panel to Debug Bar and/or Query Monitor plugins. Alternatively, go to ElasticPress > Query Log and set it to record ElasticPress queries. Requirements: ElasticPress 4.4.0+ PHP 7.4+ Additional functionalities with Debug Bar 1.0+ or Query Monitor

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C