Health Check & Troubleshooting <= 1.7.1 - Authenticated (Admin+) Path Traversal
low
The Health Check & Troubleshooting plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to perform actions on files outside of the originally intended directory.
- CVSS:
- 2.7
- Affected:
- up to 1.7.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 15, 2025
CVE-2025-64253 on NVD →
Health Check & Troubleshooting <= 1.5.1 - Cross-Site Request Forgery via health_check_troubleshoot_get_captures
medium
The Health Check & Troubleshooting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.1. This is due to missing or incorrect nonce validation on the health_check_troubleshoot_get_captures function. This makes it possible for unauthenticated attackers to enable or disa...
- CVSS:
- 6.3
- Affected:
- up to 1.5.1
- Fixed in:
- 1.6.0
- Disclosed:
- Mar 31, 2023
CVE-2022-47161 on NVD →
Health Check & Troubleshooting <= 1.2.3 - Cross-Site Request Forgery
high
The Health Check & Troubleshooting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation. This makes it possible for authenticated attackers to call AJAX actions (vulnerable actions listed in resource) via forged re...
- CVSS:
- 8
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Jan 25, 2019
Health Check & Troubleshooting <= 1.2.3 - Path Traversal
medium
The Health Check & Troubleshooting plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.2.3 via the POST parameter 'file' where it is used unchecked with 'file_get_contents'. This allows authenticated attackers to read the contents of arbitrary files on the server, which can contain...
- CVSS:
- 4.3
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Jan 25, 2019
Health Check & Troubleshooting <= 1.2.3 - Missing Authorization Checks
high
The Health Check & Troubleshooting plugin for WordPress is vulnerable to unauthorized execution of AJAX actions by subscriber level users and above in versions up to, and including 1.2.3. This is due to missing capability checks on the various functions hooked via AJAX actions in the plugin and can lead to attackers pe...
- CVSS:
- 8.8
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Jan 25, 2018
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database