Vulnerabilities and security researches forwp-email-debug wp-email-debug
Direction: ascendingJun 15, 2025
WP Email Debug # CVE-2025-5486
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 06, 2025
- Research Description
- The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the WPMDBUG_handle_settings() function in versions 1.0 to 1.1.0. This makes it possible for unauthenticated attackers to enable debugging and send all emails to an attacker controlled address and then trigger a password reset for an administrator to gain access to an administrator account.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable