HTTP Headers
HTTP Headers has 7 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; 5 are fixed and 2 remain unpatched as of September 2026. Their average CVSS score is 5.7, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high. 2023 was the busiest year with 4 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (29%). Other recurring categories include Code Injection, CRLF Injection.
5 of the records (71%) have a vendor fix, while 2 remain unpatched. The oldest unresolved one dates back to 2026.
5 independent researchers contributed these findings, most of them (2) reported by emad. HTTP Headers is installed on roughly 50,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2026-4132HTTP Headers <= 1.19.2 - Authenticated (Administrator+) External Control of File Name or Path to RCE via 'hh_htpasswd_path' and 'hh_www_authenticate_user' Parameters
Read the full analysisVulnerability Records

HTTP Headers
Author
Dimitar Ivanov
HTTP Headers gives your control over the http headers returned by your blog or website. Headers supported by HTTP Headers includes: Access-Control-Allow-Origin Access-Control-Allow-Credentials Access-Control-Max-Age Access-Control-Allow-Methods Access-Control-Allow-Headers Access-Control-Expose-Headers Age Content-Security-Policy Content-Security-Policy-Report-Only Cache-Control Clear-Site-Data Connection Content-Encoding Content-Type Cross-Origin-Embedder-Policy Cross-Origin-Opener-Policy Cross-Origin-Resource-Policy Expect-CT Expires Feature-Policy NEL Permissions-Policy Pragma P3P Referrer-Policy Report-To Strict-Transport-Security Timing-Allow-Origin Vary WWW-Authenticate X-Content-Type-Options X-DNS-Prefetch-Control X-Download-Options X-Frame-Options X-Permitted-Cross-Domain-Policies X-Powered-By X-Robots-Tag X-UA-Compatible X-XSS-Protection
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C