CVE-2026-2811CWE-113

CVE-2026-2811

Medium · published September 2, 2026

CVSS v3.1
5.4
EPSS
0%
Percentile
6.0
In the wild
Unconfirmed
What it is

The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary HTTP headers.

The record
Technical detail
CVSS v3.1
5.4 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00165 · 6.0th percentile
Weakness
CWE-113 · Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
Published
2026-09-02T19:17Z
References (1)
EPSS history
Timeline
  • 04 SEP 03:40Z
    EPSS moved — → 0%
    epss
  • 02 SEP 14:25Z
    Ajaxify Comments < 3.2 - Unauthenticated HTTP Header Injection
    cvelistv5