VYPR

Ajaxify Comments

by WordPress

CVEs (1)

  • CVE-2026-2811MedSep 2, 2026
    risk 0.35cvss 5.4epss

    The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary HTTP headers.