PT-2026-34272 · WordPress · Http Headers
Kai Aizen
·
Published
2026-04-22
·
Updated
2026-05-01
·
CVE-2026-2717
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
HTTP Headers plugin for WordPress versions prior to 1.19.3
Description
Insufficient sanitization of custom header name and value fields before they are written to the Apache .htaccess file via the
insert with markers() function allows authenticated attackers with Administrator-level access or higher to perform CRLF Injection. This involves injecting arbitrary newline characters and additional Apache directives into the .htaccess configuration file through the 'Custom Headers' settings, which can result in Apache configuration parse errors and a potential site-wide denial of service.Recommendations
Update the plugin to a version newer than 1.19.2.
As a temporary workaround, restrict access to the 'Custom Headers' settings to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Http Headers