โ† All reports

The HTTP Headers plugin for WordPress has critical security vulnerabilities that allow for CRLF Injection and Stored Cross-Site Scripting attacks.

CybersecurityTechnologyConflictWordpress SecurityApr 22, 2026score 0.172 posts ยท 0 replies across 1 instances
Two microblog posts report security vulnerabilities in the HTTP Headers plugin for WordPress, specifically CRLF Injection and Stored Cross-Site Scripting issues affecting all versions up to 1.19.2. These vulnerabilities pose risks to website security and require updates to mitigate.

Claims

The HTTP Headers plugin for WordPress has critical security vulnerabilities that allow for CRLF Injection and Stored Cross-Site Scripting attacks.
Parent: CybersecurityEntity: WordPress HTTP Headers PluginImpact: negativeDate: Apr 22, 2026Target: The security of WordPress plugins

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24634 ๐Ÿ“Š Score: 4.4/10 (CVSS v3.1) ๐Ÿ“ฆ Product: HTTP Headers ๐Ÿข Vendor: zinoui ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ The HTTP Headers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.19.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24634 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24637 ๐Ÿ“Š Score: 5.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: HTTP Headers ๐Ÿข Vendor: zinoui ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ The HTTP Headers plugin for WordPress is vulnerable to CRLF Injection in all versions up to, and including, 1.19.2. This is due to insufficient sanitization of custom header name and value fields before writing them to the Apache .htaccess file via `inse... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24637 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24674 ๐Ÿ“Š Score: 7.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: HTTP Headers ๐Ÿข Vendor: zinoui ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Execution in all versions up to and including 1.19.2. This is due to insufficient validation of the file path stored in the 'hh_htpasswd_p... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24674 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability