Junglewise Threat Intelligence

CVE-2026-57403: Milan Petrovic GD Security Headers Reflected XSS

CVE-2026-57403 · Severity: high · CVSS 7.1 · Published 2026-07-13

Executive brief

GD Security Headers is a WordPress plugin designed to enhance website security by managing HTTP security headers. A vulnerability in this plugin allows attackers to perform reflected cross-site scripting (XSS) attacks. If a site administrator or visitor clicks a specially crafted link, an attacker can execute malicious scripts in their browser, potentially leading to unauthorized actions, data theft, or website defacement.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Milan Petrovic GD Security Headers plugin for WordPress due to improper neutralization of user-supplied input during web page generation. The flaw affects versions up to and including 1.8. An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can be used to hijack administrative sessions or inject malicious payloads. The issue is addressed in version 1.9.

Affected products

  • Milan Petrovic GD Security Headers <= 1.8

Timeline

  • 2026-04-28: other: Vulnerability reported by researcher HaiND
  • 2026-07-08: advisory: Patchstack published advisory details
  • 2026-07-13: disclosed: CVE published to NVD dataset
  • 2026-07-13: patched: Version 1.9 released to address the vulnerability

References