Detects WordPress instances running the Debugger & Troubleshooter plugin version 1.3.2 or earlier, where the User Role Simulator feature accepts a raw user ID from the wp_debug_troubleshoot_simulate_user cookie without any cryptographic validation. An unauthenticated attacker sets this cookie to 1 (the default admin account) to gain full administrator access. The fix in 1.4.0 replaces the raw ID with a cryptographically signed token that requires database-backed validation.
Is your app exploitable through CVE-2026-5130?
Scan your domain free