WordPress Plugin Vulnerabilities
Ajaxify Comments < 3.2 - Unauthenticated HTTP Header Injection
Description
The plugin is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary HTTP headers.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
INJECTION
OWASP top 10
CVSS
Miscellaneous
Original Researcher
Azmi Alsarayrah
Submitter
Azmi Alsarayrah
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-02-27 (about 1 month ago)
Added
2026-02-27 (about 1 month ago)
Last Updated
2026-02-27 (about 1 month ago)