← Database

CVE-2026-2811

MEDIUM CVSS: 5.4 Published: 2026-09-02 Modified: 2026-09-02

Description

The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary HTTP headers.

Affected Platforms

Unknown

Weakness Type

CWE-113

References