PT-2025-35867 · WordPress · Atec Debug

Jonas Benjamin Friedli

·

Published

2025-09-04

·

Updated

2025-09-04

·

CVE-2025-9517

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions atec Debug plugin for WordPress versions prior to 1.2.23
Description The atec Debug plugin for WordPress is susceptible to remote code execution through the custom log parameter due to insufficient sanitization when saving the custom log path. This allows authenticated attackers with Administrator-level access or higher to execute code on the server.
Recommendations Update the atec Debug plugin to a version later than 1.2.22.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-9517

Affected Products

Atec Debug