cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forhealth-check health-check

Direction: ascending
Jun 06, 2024

Health Check & Troubleshooting # 0d7812488161d299639070e64cb97bd1b407ca30

Date
Jan 28, 2019
Research Description
Health Check &amp; Troubleshooting [health-check] < 1.2.4 WordPress Health Check & Troubleshooting plugin <= 1.2.3 - Authenticated Path Traversal vulnerability Authenticated Path Traversal vulnerability found by Julien Legras in WordPress Health Check & Troubleshooting plugin (versions <= 1.2.3).
Affected versions
max 1.2.4.
Status
vulnerable

Health Check & Troubleshooting # CVE-2022-47161

CVE, Research URL

CVE-2022-47161

Date
May 25, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions.
Affected versions
max 1.6.0.
Status
vulnerable
Jan 08, 2026

Health Check & Troubleshooting # CVE-2025-64253

CVE, Research URL

CVE-2025-64253

Date
Dec 16, 2025
Research Description
Path Traversal: '.../...//' vulnerability in WordPress.org Health Check & Troubleshooting health-check allows Path Traversal.This issue affects Health Check & Troubleshooting: from n/a through <= 1.7.1.
Affected versions
max 1.7.1.
Status
vulnerable
Jun 15, 2026

Health Check & Troubleshooting # 91697c2669648c34892b4baa03d664fcf59e0da1

Date
Mar 31, 2023
Research Description
Health Check &amp; Troubleshooting [health-check] < 1.6.0 Health Check & Troubleshooting <= 1.5.1 - Cross-Site Request Forgery via health_check_troubleshoot_get_captures The Health Check & Troubleshooting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.1. This is due to missing or incorrect nonce validation on the health_check_troubleshoot_get_captures function. This makes it possible for unauthenticated attackers to enable or disable plugins and themes, dismiss notices, or disable troubleshooting mode when the site is in troubleshooting mode via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.6.0.
Status
vulnerable

Health Check & Troubleshooting # d7145f5c-d900-49dc-a424-57e57be4e31a

Date
-
Research Description
Health Check &amp; Troubleshooting [health-check] < 1.2.4 Health Check &amp; Troubleshooting &lt;= 1.2.3 - Authenticated Lack of Authorisation The Health Check &amp; Troubleshooting WordPress plugin was affected by an Authenticated Lack of Authorisation security vulnerability.
Affected versions
max 1.2.4.
Status
vulnerable

Health Check & Troubleshooting # b7625e805d5d0048f4e47bd2822ba31d6f7345f0

Date
Jan 28, 2019
Research Description
Health Check &amp; Troubleshooting [health-check] < 1.2.4 WordPress Health Check & Troubleshooting plugin <= 1.2.3 - Authenticated Lack of Authorisation (privilege escalation) vulnerability Authenticated Lack of Authorisation vulnerability found by Julien Legras in WordPress Health Check & Troubleshooting plugin (versions <= 1.2.3).
Affected versions
max 1.2.4.
Status
vulnerable

Health Check & Troubleshooting # d8e54e591ad1c349bf6c1675d3f247a013d999a0

Date
Jan 25, 2019
Research Description
Health Check &amp; Troubleshooting [health-check] < 1.2.4 Health Check & Troubleshooting <= 1.2.3 - Path Traversal The Health Check & Troubleshooting plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.2.3 via the POST parameter 'file' where it is used unchecked with 'file_get_contents'. This allows authenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected versions
max 1.2.4.
Status
vulnerable

Health Check & Troubleshooting # 63052402-a5f3-498d-850c-eeed91c6a251

Date
-
Research Description
Health Check &amp; Troubleshooting [health-check] < 1.2.4 Health Check &amp; Troubleshooting &lt; 1.2.4 - Missing Authorization Checks The plugin is missing capability checks in several AJAX actions, allowing users with a role as low as Subscriber to perform privileged actions.
Affected versions
max 1.2.4.
Status
vulnerable

Health Check & Troubleshooting # a7669f78f29acd4eaa817c2ec2c75c835a47c0f2

Date
Jan 25, 2019
Research Description
Health Check &amp; Troubleshooting [health-check] < 1.2.4 Health Check & Troubleshooting <= 1.2.3 - Cross-Site Request Forgery The Health Check & Troubleshooting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation. This makes it possible for authenticated attackers to call AJAX actions (vulnerable actions listed in resource) via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.2.4.
Status
vulnerable

Health Check & Troubleshooting # 9021e2d622f2b4d6599f436f5c0352898f67faf5

Date
Jan 25, 2018
Research Description
Health Check &amp; Troubleshooting [health-check] < 1.2.4 Health Check & Troubleshooting <= 1.2.3 - Missing Authorization Checks The Health Check & Troubleshooting plugin for WordPress is vulnerable to unauthorized execution of AJAX actions by subscriber level users and above in versions up to, and including 1.2.3. This is due to missing capability checks on the various functions hooked via AJAX actions in the plugin and can lead to attackers performing a variety of unauthorized actions.
Affected versions
max 1.2.4.
Status
vulnerable

Health Check & Troubleshooting # 5eecc4a7-0b44-495d-9352-78dccebfc72a

Date
-
Research Description
Health Check &amp; Troubleshooting [health-check] < 1.2.4 Health Check &amp; Troubleshooting &lt;= 1.2.3 - Authenticated Path Traversal The Health Check &amp; Troubleshooting WordPress plugin was affected by an Authenticated Path Traversal security vulnerability.
Affected versions
max 1.2.4.
Status
vulnerable
Aug 25, 2026

Health Check & Troubleshooting # PSC-2026-64692

PSC, Research URL

PSC-2026-64692

Date
Aug 25, 2026
Research Description
Diagnostic plugins inspect server and WordPress configuration, collect debug data, verify files and email delivery, and alter plugin or theme state for a troubleshooting session. Health Check & Troubleshooting version 1.7.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64692, confirming that the review focused on privileged diagnostics, session isolation, debug data disclosure, file integrity checks, tool requests, and temporary troubleshooting controls.
Affected versions
Min 1.7.1, max 1.7.1.
Status
SAFE & CERTIFIED