Stored Cross-Site Scripting in HTTP Headers Plugin for WordPress
CVE-2026-1379
4.4MEDIUM
What is CVE-2026-1379?
The HTTP Headers plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping in the admin settings. This vulnerability allows authenticated users with administrator-level permissions to inject malicious web scripts into pages. These scripts can be executed whenever a user accesses a compromised page. The issue primarily affects multi-site installations, particularly those where the unfiltered_html option has been disabled.
Affected Version(s)
HTTP Headers 0 <= 1.19.2