Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary HTTP headers. | |
| Title | Ajaxify Comments < 3.2 - Unauthenticated HTTP Header Injection | |
| Weaknesses | CWE-113 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-02T14:57:35.380Z
Reserved: 2026-02-19T15:54:12.930Z
Link: CVE-2026-2811
Updated: 2026-09-02T14:42:50.790Z
Status : Received
Published: 2026-09-02T15:17:38.270
Modified: 2026-09-02T15:17:38.270
Link: CVE-2026-2811
No data.
OpenCVE Enrichment
No data.
-
CWE-113
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')