← back to popular plugins
wordfence / plugin · health-check
Health Check & Troubleshooting
health-check
total installs
300,000
total vulns
1
critical
0
high
0
medium
0
low
1
latest vuln
—
patched
0
unpatched
1
avg time to patch
—
vulnerabilities
(1)
Health Check & Troubleshooting <= 1.7.1 - Authenticated (Admin+) Path Traversal
low
✕ unpatched
cve id
CVE-2025-64253 ↗
cvss score
2.7
cwe
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
published
Dec 15, 2025
The Health Check & Troubleshooting plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to perform actions on files outside of the originally intended directory.