Impact
The Ajaxify Comments WordPress plugin, versions prior to 3.2, accepts user-supplied data without proper sanitization or escaping, allowing attackers to inject arbitrary HTTP headers into responses. This weakness can alter the behavior of the web server or client by modifying headers such as Set-Cookie, Location, or others, potentially facilitating further attacks such as phishing, redirect manipulation, or session hijacking. The vulnerability is exploitable by unauthenticated users, as any visitor can send crafted HTTP requests containing malicious header payloads.
Affected Systems
This vulnerability affects the Ajaxify Comments plugin for WordPress in all releases older than version 3.2. The exact CPE identifiers are not listed, but the vendor/product name is "Ajaxify Comments" and the critical version threshold is 3.2. Systems running the plugin without applying the 3.2 or newer release are at risk.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known large‑scale exploitation activity. Attackers can inject headers remotely without authentication by sending specially crafted HTTP requests to the affected WordPress site. Although no public exploit has been documented, the lack of input filtering makes the vulnerability straightforward to leverage for modifying response headers.
OpenCVE Enrichment