The HTTP Headers plugin for WordPress has critical security vulnerabilities that allow for CRLF Injection and Stored Cross-Site Scripting attacks.
Claims
The HTTP Headers plugin for WordPress has critical security vulnerabilities that allow for CRLF Injection and Stored Cross-Site Scripting attacks.
Parent: CybersecurityEntity: WordPress HTTP Headers PluginImpact: negativeDate: Apr 22, 2026Target: The security of WordPress plugins
Source posts
๐จ EUVD-2026-24634
๐ Score: 4.4/10 (CVSS v3.1)
๐ฆ Product: HTTP Headers
๐ข Vendor: zinoui
๐
Updated: 2026-04-22
๐ The HTTP Headers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.19.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24634
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24637
๐ Score: 5.5/10 (CVSS v3.1)
๐ฆ Product: HTTP Headers
๐ข Vendor: zinoui
๐
Updated: 2026-04-22
๐ The HTTP Headers plugin for WordPress is vulnerable to CRLF Injection in all versions up to, and including, 1.19.2. This is due to insufficient sanitization of custom header name and value fields before writing them to the Apache .htaccess file via `inse...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24637
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24674
๐ Score: 7.2/10 (CVSS v3.1)
๐ฆ Product: HTTP Headers
๐ข Vendor: zinoui
๐
Updated: 2026-04-22
๐ The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Execution in all versions up to and including 1.19.2. This is due to insufficient validation of the file path stored in the 'hh_htpasswd_p...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24674
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability