WordPress Plugin Vulnerabilities

Ajaxify Comments < 3.2 - Unauthenticated HTTP Header Injection

Description

The plugin is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary HTTP headers.

Proof of Concept

Affects Plugins

References

Classification

Type
INJECTION
OWASP top 10

Miscellaneous

Original Researcher
Azmi Alsarayrah
Submitter
Azmi Alsarayrah
Verified
Yes

Timeline

Publicly Published
2026-02-27 (about 1 month ago)
Added
2026-02-27 (about 1 month ago)
Last Updated
2026-02-27 (about 1 month ago)

Other