Unintended functionality vulnerability in Guzzlehttp/psr7 library (2 plugins affected)

The issue is with the library itself and the library must be updated to the fixed versions. Guzzlehttp/psr7 is a library used in some plugins and themes for WordPress. A vulnerability has been discovered that would allow an attacker to sneak extra information into header names and values. This vulnerability has been addressed in versions 1.9.1 and 2.4.5. There are no known workarounds for this vulnerability and WordPress users should upgrade to the fixed versions.

Detected in:

WP Offload SES Lite fixed vulnerable versions: >= * < 1.6.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.