Health Check & Troubleshooting

Health Check & Troubleshooting has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2018 and 2025; 4 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2019 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (40%). Other recurring categories include Path Traversal, Missing Authorization.

4 of the records (80%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.

3 independent researchers contributed these findings, most of them (3) reported by Julien Legras. Health Check & Troubleshooting is installed on roughly 200,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.

Strategic Overview

Avg CVSSMedium
6.0/ 10
Patch Coverage80%
Open

1

Fixed

4

Get automatic notifications for all Health Check & Troubleshooting vulnerabilities before they are exploited.

Most severe open issueCVSS 2.7CVE-2025-64253

Health Check & Troubleshooting <= 1.7.1 - Authenticated (Admin+) Path Traversal

Read the full analysis

Vulnerability Records

5 records
Health Check & Troubleshooting banner
Latestv1.7.1

Health Check & Troubleshooting

WordPress.org

Author

WordPress.org

3.6(181)
72/100
Last Updated
2024-07-25 (2y ago)
Active Installs
200,000+
Downloads
5,356,563
Requires WP
4.4+
Requires PHP
5.6+
Tested up to
WP 6.6.7
Created
2018-06-09 (8y ago)

This plugin will perform a number of checks on your WordPress installation to detect common configuration errors and known issues, and also allows plugins and themes to add their own checks. The debug section, which allows you to gather information about your WordPress and server configuration that you may easily share with support representatives for themes, plugins or on the official WordPress.org support forums. Troubleshooting allows you to have a clean WordPress session, where all plugins are disabled, and a default theme is used, but only for your user until you disable it or log out. The Tools section allows you to check that WordPress files have not been tampered with, that emails can be sent, and if your plugins are compatible with any PHP version updates in the future. For a more extensive example of how to efficiently use the Health Check plugin, check out the WordPress.org support team handbook page about this plugin. Feedback is welcome both through the WordPress.org forums, the GitHub project page, or on Slack in either #forums or #core-site-health.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C