Debug Bar – Enable WP_DEBUG from admin dashboard

Debug Bar – Enable WP_DEBUG from admin dashboard has one disclosed vulnerability in the WordSec catalog, all reported in 2022; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Debug Bar – Enable WP_DEBUG from admin dashboard has a vendor fix available, so running the current release closes it.

All of these findings were reported by WPScanTeam. Debug Bar – Enable WP_DEBUG from admin dashboard is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Debug Bar – Enable WP_DEBUG from admin dashboard vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1

Debug Bar <= 1.85 - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Debug Bar – Enable WP_DEBUG from admin dashboard banner
Latestv1.93

Debug Bar – Enable WP_DEBUG from admin dashboard

Puvox Software

Author

Puvox Software

1.8(5)
36/100
Last Updated
2024-10-30 (2y ago)
Active Installs
100+
Downloads
16,071
Requires WP
6.0+
Requires PHP
0+
Tested up to
WP 6.5.10
Created
2017-12-30 (9y ago)

[ ✅ 𝐒𝐄𝐂𝐔𝐑𝐄 𝐏𝐋𝐔𝐆𝐈𝐍𝐒 b𝓎 𝒫𝓊𝓋𝑜𝓍] : • Revised for security to be reliable and free of vulnerability holes. • Efficient, not to add any extra load/slowness to site. • Don’t collect private data. Plugin Description READ DESCRIPTION BEFORE INSTALLING! Easily enable/disable WP_DEBUG with one single click from Admin Toolbar. What’s more, this plugin is failsafe & clever – in case of errors, it automatically exits the WP_DEBUG mode, thus, you won’t face any problems. Works with Debug Bar plugin. NOTE Plugin modifies wp-config.php. However, on some sites, this might cause some conflict with existing wp-config, causing to interfere the page-load. So, use at your own responsibility. If unsure, use on test site. Available Options See all available options and their description on plugin’s settings page.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C