Debug Tool <= 2.2 - Unauthenticated Remote Code Execution
critical
The Debug Tool plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 2.2
- Fix:
- No patched version reported
- Disclosed:
- Nov 13, 2025
CVE-2024-52416 on NVD →
Debug Tool [debug-tool] <= 2.2 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in Eugen Bobrowski Debug Tool allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Debug Tool: from n/a through 2.2.
- Affected:
- up to 2.2
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2025
CVE-2025-23684 on NVD →
Debug Tool <= 2.2 - Missing Authorization
medium
The Debug Tool plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.2
- Fix:
- No patched version reported
- Disclosed:
- Jan 16, 2025
CVE-2025-23684 on NVD →
Debug Tool [debug-tool] <= 2.2 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in Eugen Bobrowski Debug Tool allows Upload a Web Shell to a Web Server.This issue affects Debug Tool: from n/a through 2.2.
- Affected:
- up to 2.2
- Fix:
- No patched version reported
- Disclosed:
- Nov 16, 2024
CVE-2024-52416 on NVD →
Debug Tool [debug-tool] <= 2.2 (unfixed + closed)
unknown
[en] The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and missing file type validation in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to to create arbitrary files such as .php...
- Affected:
- up to 2.2
- Fix:
- No patched version reported
- Disclosed:
- Nov 9, 2024
CVE-2024-10586 on NVD →
Debug Tool [debug-tool] <= 2.2 (unfixed + closed)
unknown
[en] The Debug Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the info() function in all versions up to, and including, 2.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to obtain information from phpinfo(). When...
- Affected:
- up to 2.2
- Fix:
- No patched version reported
- Disclosed:
- Nov 9, 2024
CVE-2024-10588 on NVD →
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
critical
The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and missing file type validation in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to to create arbitrary files such as .php files...
- CVSS:
- 9.8
- Affected:
- up to 2.2
- Fix:
- No patched version reported
- Disclosed:
- Nov 8, 2024
CVE-2024-10586 on NVD →
Debug Tool <= 2.2 - Missing Authorization to Information Exposure
medium
The Debug Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the info() function in all versions up to, and including, 2.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to obtain information from phpinfo(). When WP_D...
- CVSS:
- 4.3
- Affected:
- up to 2.2
- Fix:
- No patched version reported
- Disclosed:
- Nov 8, 2024
CVE-2024-10588 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database