GD Security Headers

GD Security Headers has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 2 high. 2023 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include SQL Injection.

Every one of the 3 issues recorded for GD Security Headers has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. GD Security Headers is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.8/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all GD Security Headers vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.2CVE-2026-57403

GD Security Headers <= 1.8 - Unauthenticated Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

3 records
GD Security Headers banner
Latestv1.9

GD Security Headers

Milan Petrovic

Author

Milan Petrovic

4.0(8)
80/100
Last Updated
2026-05-12 (4mo ago)
Active Installs
1,000+
Downloads
34,929
Requires WP
5.5+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2019-03-28 (8y ago)

Configure various security-related HTTP headers, including Content Security Policy, Feature Policy, Referrer Policy and more. For CSP and XSS plugin supports report logging with 2 additional database tables to store reports from browsers. Supported security headers The plugin has support for the following HTTP headers: Content Security Policy (CSP) – with reporting XSS Protection (XXP) – with reporting Feature Policy (Permissions Policy) Content Type – No Sniff Policy Strict Transport Security Referrer Policy Frame Options For CSP, the plugin allows you to set rules for all currently supported directives, additional settings including setting the policy in Report or Live mode. The plugin also includes special extensions that can automatically fill CSP rules for popular Google services you might be using on your website (Fonts, Maps, Adsense, Analytics, TagManager and more) and other popular services (Gravatar, Instagram, PayPal Vimeo and more). And, for Feature Policy (or Permissions Policy), the plugin allows you to set rules for all currently supported rules (over 25 rules, supported by different browsers). FLoC / Browsing Topics Permissions Policy rules list includes &#8216;browsing-topics’ rule that can be used to disable Google’s new tracking method &#8216;Browsing Topics API’ (which replaced &#8216;Federated Learning of Cohorts’ or &#8216;FLoC’). Methods for adding headers The plugin can add all the generated headers into HTACCESS file (for Apache web servers), and they will be applied to all files, not just WordPress generated content. If your website is not using Apache (or .HTACCESS), all rules are generated with each page request and will work with any server type. And, if you don’t use Apache web server, the plugin has a panel where it displays generated headers for most popular servers: Apache, Nginx and IIS, and you can copy generated headers to add to server configuration files. About the plugin More information about GD Security Headers Support and Knowledge Base for GD Security Headers

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C