plugin

Debug Tool Vulnerabilities

8 known security issues reported for the Debug Tool WordPress plugin. Most recent disclosed Nov 13, 2025.

2 critical 2 medium

Running Debug Tool on your site? Check whether your installed version is affected.

Scan your site free

Debug Tool <= 2.2 - Unauthenticated Remote Code Execution

critical

The Debug Tool plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 2.2
Fix:
No patched version reported
Disclosed:
Nov 13, 2025

CVE-2024-52416 on NVD →

Debug Tool [debug-tool] <= 2.2 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in Eugen Bobrowski Debug Tool allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Debug Tool: from n/a through 2.2.

Affected:
up to 2.2
Fix:
No patched version reported
Disclosed:
Jan 22, 2025

CVE-2025-23684 on NVD →

Debug Tool <= 2.2 - Missing Authorization

medium

The Debug Tool plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.2
Fix:
No patched version reported
Disclosed:
Jan 16, 2025

CVE-2025-23684 on NVD →

Debug Tool [debug-tool] <= 2.2 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in Eugen Bobrowski Debug Tool allows Upload a Web Shell to a Web Server.This issue affects Debug Tool: from n/a through 2.2.

Affected:
up to 2.2
Fix:
No patched version reported
Disclosed:
Nov 16, 2024

CVE-2024-52416 on NVD →

Debug Tool [debug-tool] <= 2.2 (unfixed + closed)

unknown

[en] The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and missing file type validation in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to to create arbitrary files such as .php...

Affected:
up to 2.2
Fix:
No patched version reported
Disclosed:
Nov 9, 2024

CVE-2024-10586 on NVD →

Debug Tool [debug-tool] <= 2.2 (unfixed + closed)

unknown

[en] The Debug Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the info() function in all versions up to, and including, 2.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to obtain information from phpinfo(). When...

Affected:
up to 2.2
Fix:
No patched version reported
Disclosed:
Nov 9, 2024

CVE-2024-10588 on NVD →

Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation

critical

The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and missing file type validation in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to to create arbitrary files such as .php files...

CVSS:
9.8
Affected:
up to 2.2
Fix:
No patched version reported
Disclosed:
Nov 8, 2024

CVE-2024-10586 on NVD →

Debug Tool <= 2.2 - Missing Authorization to Information Exposure

medium

The Debug Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the info() function in all versions up to, and including, 2.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to obtain information from phpinfo(). When WP_D...

CVSS:
4.3
Affected:
up to 2.2
Fix:
No patched version reported
Disclosed:
Nov 8, 2024

CVE-2024-10588 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database