Vulnerabilities and security researches forhealth-check health-check
Direction: ascendingJun 06, 2024
Health Check & Troubleshooting # 0d7812488161d299639070e64cb97bd1b407ca30
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 28, 2019
- Research Description
- Health Check & Troubleshooting [health-check] < 1.2.4 WordPress Health Check & Troubleshooting plugin <= 1.2.3 - Authenticated Path Traversal vulnerability Authenticated Path Traversal vulnerability found by Julien Legras in WordPress Health Check & Troubleshooting plugin (versions <= 1.2.3).
- Affected versions
-
max 1.2.4.
- Status
-
vulnerable
Health Check & Troubleshooting # CVE-2022-47161
- CVE, Research URL
- Home page URL
- Application
- Date
- May 25, 2023
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions.
- Affected versions
-
max 1.6.0.
- Status
-
vulnerable
Jan 08, 2026
Health Check & Troubleshooting # CVE-2025-64253
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 16, 2025
- Research Description
- Path Traversal: '.../...//' vulnerability in WordPress.org Health Check & Troubleshooting health-check allows Path Traversal.This issue affects Health Check & Troubleshooting: from n/a through <= 1.7.1.
- Affected versions
-
max 1.7.1.
- Status
-
vulnerable
Jun 15, 2026
Health Check & Troubleshooting # 91697c2669648c34892b4baa03d664fcf59e0da1
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 31, 2023
- Research Description
- Health Check & Troubleshooting [health-check] < 1.6.0 Health Check & Troubleshooting <= 1.5.1 - Cross-Site Request Forgery via health_check_troubleshoot_get_captures The Health Check & Troubleshooting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.1. This is due to missing or incorrect nonce validation on the health_check_troubleshoot_get_captures function. This makes it possible for unauthenticated attackers to enable or disable plugins and themes, dismiss notices, or disable troubleshooting mode when the site is in troubleshooting mode via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 1.6.0.
- Status
-
vulnerable
Health Check & Troubleshooting # d7145f5c-d900-49dc-a424-57e57be4e31a
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Health Check & Troubleshooting [health-check] < 1.2.4 Health Check & Troubleshooting <= 1.2.3 - Authenticated Lack of Authorisation The Health Check & Troubleshooting WordPress plugin was affected by an Authenticated Lack of Authorisation security vulnerability.
- Affected versions
-
max 1.2.4.
- Status
-
vulnerable
Health Check & Troubleshooting # b7625e805d5d0048f4e47bd2822ba31d6f7345f0
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 28, 2019
- Research Description
- Health Check & Troubleshooting [health-check] < 1.2.4 WordPress Health Check & Troubleshooting plugin <= 1.2.3 - Authenticated Lack of Authorisation (privilege escalation) vulnerability Authenticated Lack of Authorisation vulnerability found by Julien Legras in WordPress Health Check & Troubleshooting plugin (versions <= 1.2.3).
- Affected versions
-
max 1.2.4.
- Status
-
vulnerable
Health Check & Troubleshooting # d8e54e591ad1c349bf6c1675d3f247a013d999a0
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 25, 2019
- Research Description
- Health Check & Troubleshooting [health-check] < 1.2.4 Health Check & Troubleshooting <= 1.2.3 - Path Traversal The Health Check & Troubleshooting plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.2.3 via the POST parameter 'file' where it is used unchecked with 'file_get_contents'. This allows authenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- Affected versions
-
max 1.2.4.
- Status
-
vulnerable
Health Check & Troubleshooting # 63052402-a5f3-498d-850c-eeed91c6a251
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Health Check & Troubleshooting [health-check] < 1.2.4 Health Check & Troubleshooting < 1.2.4 - Missing Authorization Checks The plugin is missing capability checks in several AJAX actions, allowing users with a role as low as Subscriber to perform privileged actions.
- Affected versions
-
max 1.2.4.
- Status
-
vulnerable
Health Check & Troubleshooting # a7669f78f29acd4eaa817c2ec2c75c835a47c0f2
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 25, 2019
- Research Description
- Health Check & Troubleshooting [health-check] < 1.2.4 Health Check & Troubleshooting <= 1.2.3 - Cross-Site Request Forgery The Health Check & Troubleshooting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation. This makes it possible for authenticated attackers to call AJAX actions (vulnerable actions listed in resource) via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 1.2.4.
- Status
-
vulnerable
Health Check & Troubleshooting # 9021e2d622f2b4d6599f436f5c0352898f67faf5
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 25, 2018
- Research Description
- Health Check & Troubleshooting [health-check] < 1.2.4 Health Check & Troubleshooting <= 1.2.3 - Missing Authorization Checks The Health Check & Troubleshooting plugin for WordPress is vulnerable to unauthorized execution of AJAX actions by subscriber level users and above in versions up to, and including 1.2.3. This is due to missing capability checks on the various functions hooked via AJAX actions in the plugin and can lead to attackers performing a variety of unauthorized actions.
- Affected versions
-
max 1.2.4.
- Status
-
vulnerable
Health Check & Troubleshooting # 5eecc4a7-0b44-495d-9352-78dccebfc72a
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Health Check & Troubleshooting [health-check] < 1.2.4 Health Check & Troubleshooting <= 1.2.3 - Authenticated Path Traversal The Health Check & Troubleshooting WordPress plugin was affected by an Authenticated Path Traversal security vulnerability.
- Affected versions
-
max 1.2.4.
- Status
-
vulnerable
Aug 25, 2026
Health Check & Troubleshooting # PSC-2026-64692
- PSC, Research URL
- Home page URL
- Application
- Date
- Aug 25, 2026
- Research Description
- Diagnostic plugins inspect server and WordPress configuration, collect debug data, verify files and email delivery, and alter plugin or theme state for a troubleshooting session. Health Check & Troubleshooting version 1.7.1 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64692, confirming that the review focused on privileged diagnostics, session isolation, debug data disclosure, file integrity checks, tool requests, and temporary troubleshooting controls.
- Affected versions
-
Min 1.7.1, max 1.7.1.
- Status
-
SAFE & CERTIFIED