PT-2025-35867 · WordPress · Atec Debug

Jonas Benjamin Friedli

·

Published

2025-09-04

·

Updated

2025-09-04

·

CVE-2025-9517

CVSS v3.1
7.2
VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

atec Debug plugin for WordPress versions prior to 1.2.23

Description:

The atec Debug plugin for WordPress is susceptible to remote code execution through the `custom log` parameter due to insufficient sanitization when saving the custom log path. This allows authenticated attackers with Administrator-level access or higher to execute code on the server.

Recommendations:

Update the atec Debug plugin to a version later than 1.2.22.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-9517

Affected Products

Atec Debug