WP Email Debug
WP Email Debug has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for WP Email Debug has a vendor fix available, so running the current release closes it.
All of these findings were reported by kr0d. WP Email Debug is installed on roughly 80 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-5486WP Email Debug 1.0 - 1.1.0 - Missing Authorization to Unauthenticated Privilege Escalation via Password Reset
Read the full analysisVulnerability Records

WP Email Debug
Author
Grant Derepas
This plugin makes it safe and easy to work with email in your testing environments. When enabled the plugin catches any instance of wp_mail and redirects the email to your chosen email address. Key Features Set a custom email address target to redirect emails to Emails intercepted will have [Debug] added to the subject line to make them identifyable in your inbox Interception rules can be limited by plugin allowing you to debug a specific plugin on your live site without affecting other operations Notice in the WP Admin Bar when enabled. For Bugs Reports or to contribute Please visit our public GitHub Repo
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C