Title: Vulnerability Reported
Last modified: September 23, 2026

---

# Vulnerability Reported

 *  [dpmcalister](https://wordpress.org/support/users/dpmcalister/)
 * (@dpmcalister)
 * [1 week ago](https://wordpress.org/support/topic/vulnerability-reported-8/)
 * Wordfence are reporting another vulnerability with this plugin: [https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/http-headers/http-headers-1192-authenticated-administrator-crlf-injection-via-custom-header-values](https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/http-headers/http-headers-1192-authenticated-administrator-crlf-injection-via-custom-header-values)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fvulnerability-reported-8%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/http-headers/assets/icon-128x128.png?rev=1413576)
 * [HTTP Headers](https://wordpress.org/plugins/http-headers/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/http-headers/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/http-headers/)
 * [Active Topics](https://wordpress.org/support/plugin/http-headers/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/http-headers/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/http-headers/reviews/)

 * 0 replies
 * 1 participant
 * Last reply from: [dpmcalister](https://wordpress.org/support/users/dpmcalister/)
 * Last activity: [1 week ago](https://wordpress.org/support/topic/vulnerability-reported-8/)
 * Status: not resolved