The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation on the 'debug_path' parameter in all versions up to, and including, 1.2.22. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
                
            References
                    Configurations
                    No configuration.
History
                    04 Sep 2025, 10:42
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-09-04 10:42
Updated : 2025-09-04 15:35
NVD link : CVE-2025-9518
Mitre link : CVE-2025-9518
CVE.ORG link : CVE-2025-9518
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-36
                        
            Absolute Path Traversal
