PT-2026-34272 · WordPress · Http Headers

Kai Aizen

·

Published

2026-04-22

·

Updated

2026-05-01

·

CVE-2026-2717

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions HTTP Headers plugin for WordPress versions prior to 1.19.3
Description Insufficient sanitization of custom header name and value fields before they are written to the Apache .htaccess file via the insert with markers() function allows authenticated attackers with Administrator-level access or higher to perform CRLF Injection. This involves injecting arbitrary newline characters and additional Apache directives into the .htaccess configuration file through the 'Custom Headers' settings, which can result in Apache configuration parse errors and a potential site-wide denial of service.
Recommendations Update the plugin to a version newer than 1.19.2. As a temporary workaround, restrict access to the 'Custom Headers' settings to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2717

Affected Products

Http Headers