WordPress Plugin HTTP Headers is prone to multiple vulnerabilities, including server-side request forgery and cross-site request forgery vulnerabilities. Exploiting these issues could allow an attacker to make the vulnerable server perform port scanning of hosts in internal or external networks, or to perform certain administrative actions and gain unauthorized access to the affected application. WordPress Plugin HTTP Headers version 1.9.1 is vulnerable; prior versions may also be affected.
Update to plugin version 1.9.4 or latest
WordPress Plugin Search Unleashed 'Log' Function HTML Injection (0.2.10)
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.23)
Apache Tomcat version older than 6.0.18
WordPress Plugin Google Authenticator Unspecified Vulnerability (0.47)
WordPress Plugin Duplicate Page Multiple Vulnerabilities (2.3)