HTTP Headers

HTTP Headers has 7 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; 5 are fixed and 2 remain unpatched as of September 2026. Their average CVSS score is 5.7, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high. 2023 was the busiest year with 4 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (29%). Other recurring categories include Code Injection, CRLF Injection.

5 of the records (71%) have a vendor fix, while 2 remain unpatched. The oldest unresolved one dates back to 2026.

5 independent researchers contributed these findings, most of them (2) reported by emad. HTTP Headers is installed on roughly 50,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
5.7/ 10
Patch Coverage71%
Open

2

Fixed

5

Get automatic notifications for all HTTP Headers vulnerabilities before they are exploited.

Most severe open issueCVSS 7.2CVE-2026-4132

HTTP Headers <= 1.19.2 - Authenticated (Administrator+) External Control of File Name or Path to RCE via 'hh_htpasswd_path' and 'hh_www_authenticate_user' Parameters

Read the full analysis

Vulnerability Records

7 records
HTTP Headers banner
Latestv1.19.5
4.3(70)
86/100
Last Updated
2026-04-27 (5mo ago)
Active Installs
50,000+
Downloads
783,614
Requires WP
3.2+
Requires PHP
5.3+
Tested up to
WP 6.9.7
Created
2016-05-10 (11y ago)

HTTP Headers gives your control over the http headers returned by your blog or website. Headers supported by HTTP Headers includes: Access-Control-Allow-Origin Access-Control-Allow-Credentials Access-Control-Max-Age Access-Control-Allow-Methods Access-Control-Allow-Headers Access-Control-Expose-Headers Age Content-Security-Policy Content-Security-Policy-Report-Only Cache-Control Clear-Site-Data Connection Content-Encoding Content-Type Cross-Origin-Embedder-Policy Cross-Origin-Opener-Policy Cross-Origin-Resource-Policy Expect-CT Expires Feature-Policy NEL Permissions-Policy Pragma P3P Referrer-Policy Report-To Strict-Transport-Security Timing-Allow-Origin Vary WWW-Authenticate X-Content-Type-Options X-DNS-Prefetch-Control X-Download-Options X-Frame-Options X-Permitted-Cross-Domain-Policies X-Powered-By X-Robots-Tag X-UA-Compatible X-XSS-Protection

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C