Remote Code Execution Vulnerability in atec Debug Plugin for WordPress
CVE-2025-9517
7.2HIGH
What is CVE-2025-9517?
The atec Debug plugin for WordPress suffers from a remote code execution vulnerability due to inadequate sanitization of the 'custom_log' parameter when saving the custom log path. This flaw allows authenticated users with Administrator-level privileges and higher to execute arbitrary code on the server, potentially compromising the entire system.
Affected Version(s)
atec Debug * <= 1.2.22