SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-2811

MEDIUM · CVSS 5.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Ajaxify Comments plugin for WordPress versions prior to 3.2 is susceptible to HTTP Header Injection due to inadequate input sanitization and output escaping of user-supplied data. This vulnerability allows unauthenticated attackers to inject arbitrary HTTP headers, potentially leading to various attacks such as session hijacking or cross-site scripting. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-2811
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%
WordPress

Original NVD Description

The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary HTTP headers.