HTTP Header Injection Vulnerability in Ajaxify Comments Plugin by WordPress
CVE-2026-2811
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 2 September 2026
Badges
What is CVE-2026-2811?
The Ajaxify Comments WordPress plugin prior to version 3.2 is susceptible to HTTP Header Injection. This vulnerability arises from inadequate input sanitization and output escaping of data provided by users. As a result, unauthenticated attackers could potentially inject arbitrary HTTP headers, which may lead to further exploitation or malicious activities. Website administrators should ensure they update to the latest version of the plugin to mitigate associated risks.
Affected Version(s)
Ajaxify Comments 0 < 3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved