plugin

Health Check Vulnerabilities

5 known security issues reported for the Health Check WordPress plugin. Most recent disclosed Dec 15, 2025.

2 high 2 medium 1 low

Running Health Check on your site? Check whether your installed version is affected.

Scan your site free

Health Check & Troubleshooting <= 1.7.1 - Authenticated (Admin+) Path Traversal

low

The Health Check & Troubleshooting plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to perform actions on files outside of the originally intended directory.

CVSS:
2.7
Affected:
up to 1.7.1
Fix:
No patched version reported
Disclosed:
Dec 15, 2025

CVE-2025-64253 on NVD →

Health Check & Troubleshooting <= 1.5.1 - Cross-Site Request Forgery via health_check_troubleshoot_get_captures

medium

The Health Check & Troubleshooting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.1. This is due to missing or incorrect nonce validation on the health_check_troubleshoot_get_captures function. This makes it possible for unauthenticated attackers to enable or disa...

CVSS:
6.3
Affected:
up to 1.5.1
Fixed in:
1.6.0
Disclosed:
Mar 31, 2023

CVE-2022-47161 on NVD →

Health Check & Troubleshooting <= 1.2.3 - Cross-Site Request Forgery

high

The Health Check & Troubleshooting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation. This makes it possible for authenticated attackers to call AJAX actions (vulnerable actions listed in resource) via forged re...

CVSS:
8
Affected:
up to 1.2.3
Fixed in:
1.2.4
Disclosed:
Jan 25, 2019

Health Check & Troubleshooting <= 1.2.3 - Path Traversal

medium

The Health Check & Troubleshooting plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.2.3 via the POST parameter 'file' where it is used unchecked with 'file_get_contents'. This allows authenticated attackers to read the contents of arbitrary files on the server, which can contain...

CVSS:
4.3
Affected:
up to 1.2.3
Fixed in:
1.2.4
Disclosed:
Jan 25, 2019

Health Check & Troubleshooting <= 1.2.3 - Missing Authorization Checks

high

The Health Check & Troubleshooting plugin for WordPress is vulnerable to unauthorized execution of AJAX actions by subscriber level users and above in versions up to, and including 1.2.3. This is due to missing capability checks on the various functions hooked via AJAX actions in the plugin and can lead to attackers pe...

CVSS:
8.8
Affected:
up to 1.2.3
Fixed in:
1.2.4
Disclosed:
Jan 25, 2018

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database