plugin

Debugger Troubleshooter Vulnerabilities

2 known security issues reported for the Debugger Troubleshooter WordPress plugin. Most recent disclosed Mar 30, 2026.

1 critical 1 high

Running Debugger Troubleshooter on your site? Check whether your installed version is affected.

Scan your site free

Debugger & Troubleshooter - Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation vulnerability

critical

Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation vulnerability

CVSS:
9.8
Affected:
up to 1.3.2
Fixed in:
1.4.0
Disclosed:
Mar 30, 2026

Debugger & Troubleshooter <= 1.3.2 - Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation

high

The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up to and including 1.3.2. This was due to the plugin accepting the wp_debug_troubleshoot_simulate_user cookie value directly as a user ID without any cryptographic validation or authorization checks. T...

CVSS:
8.8
Affected:
up to 1.3.2
Fixed in:
1.4.0
Disclosed:
Mar 30, 2026

CVE-2026-5130 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database