Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Security Headers gd-security-headers allows Reflected XSS.This issue affects GD Security Headers: from n/a through <= 1.8.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The GD Security Headers plugin for WordPress contains an improper neutralization of input during web page generation that allows reflected cross‑site scripting. When an attacker supplies crafted data, it is reflected back into a web page without sanitization, enabling the injection of arbitrary scripts that will execute in the victim browser.

Affected Systems

The vulnerability is present in the Milan Petrovic GD Security Headers plugin for WordPress in all releases up through version 1.8 inclusive. No later versions are known to be affected.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate‑to‑high severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation in the immediate future. The flaw is not listed in the CISA KEV catalog. Attackers can exploit this via a reflected XSS attack, requiring no authentication or privileged access, provided the plugin is active and the target site accepts external input.

Generated by OpenCVE AI on July 31, 2026 at 11:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the GD Security Headers plugin to a version that resolves the XSS flaw or remove the plugin entirely
  • If upgrading is not possible, disable the plugin to prevent the exploitation of the vulnerable code
  • Implement proper input sanitization and output escaping for any user‑supplied data that is processed or displayed by the plugin

Generated by OpenCVE AI on July 31, 2026 at 11:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Milan Petrovic
Milan Petrovic gd Security Headers
Wordpress
Wordpress wordpress
Vendors & Products Milan Petrovic
Milan Petrovic gd Security Headers
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Security Headers gd-security-headers allows Reflected XSS.This issue affects GD Security Headers: from n/a through <= 1.8.
Title WordPress GD Security Headers plugin <= 1.8 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Milan Petrovic Gd Security Headers
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:52.788Z

Reserved: 2026-06-24T12:46:27.804Z

Link: CVE-2026-57403

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:25.470Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')