Health Check & Troubleshooting
Health Check & Troubleshooting has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2018 and 2025; 4 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2019 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (40%). Other recurring categories include Path Traversal, Missing Authorization.
4 of the records (80%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
3 independent researchers contributed these findings, most of them (3) reported by Julien Legras. Health Check & Troubleshooting is installed on roughly 200,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.
CVE-2025-64253Health Check & Troubleshooting <= 1.7.1 - Authenticated (Admin+) Path Traversal
Read the full analysisVulnerability Records

Health Check & Troubleshooting
Author
WordPress.org
This plugin will perform a number of checks on your WordPress installation to detect common configuration errors and known issues, and also allows plugins and themes to add their own checks. The debug section, which allows you to gather information about your WordPress and server configuration that you may easily share with support representatives for themes, plugins or on the official WordPress.org support forums. Troubleshooting allows you to have a clean WordPress session, where all plugins are disabled, and a default theme is used, but only for your user until you disable it or log out. The Tools section allows you to check that WordPress files have not been tampered with, that emails can be sent, and if your plugins are compatible with any PHP version updates in the future. For a more extensive example of how to efficiently use the Health Check plugin, check out the WordPress.org support team handbook page about this plugin. Feedback is welcome both through the WordPress.org forums, the GitHub project page, or on Slack in either #forums or #core-site-health.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C