CRLF Injection Vulnerability in HTTP Headers Plugin for WordPress
CVE-2026-2717
5.5MEDIUM
What is CVE-2026-2717?
The HTTP Headers plugin for WordPress is susceptible to CRLF Injection due to inadequate sanitization of input in custom header fields. This vulnerability allows authenticated users with Administrator-level access to inject arbitrary newline characters into the .htaccess file via the plugin's settings. Such injections can lead to Apache configuration parse errors, resulting in potential site-wide denial of service and disruption of normal operations. Ensure your site is secure by regularly updating the plugin to avoid exploitation.
Affected Version(s)
HTTP Headers 0 <= 1.19.2