WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by Jeff Starr v3.7

Host Header Injection Fix

Sets custom headers for WP notification emails. Also fixes a security issue with WP versions < 5.5.

Host Header Injection Fix

The facts

Rating
5★ from 6
Active installs
400+
Price
Free
Last updated
18 Jul 2026
Added
Nov 2017
Requires WP
4.7
Tested up to
WP 7.1
Requires PHP
5.6.20
Downloads
27,202

Our analysis

AI-assisted

Host Header Injection Fix is a WordPress plugin designed to address specific email header issues and security vulnerabilities in versions of WordPress prior to 5.5. It allows you to set custom 'From', 'Name', and 'Return-Path' headers for notification emails, which can help prevent the generation of invalid email addresses.

The plugin is particularly relevant for users running older versions of WordPress, as it fixes a known security issue related to host-header injection. For those using WordPress 5.5 or later, the primary function of this plugin may no longer be necessary.

Best for: This plugin suits users of older WordPress versions concerned about email security and header configurations.

What it does well

  • Sets custom email headers for notifications
  • Fixes a security vulnerability in WordPress versions < 5.5
  • Prevents generation of invalid email addresses

Where it falls short

  • Not necessary for WordPress 5.5 and above
  • Limited to specific email header configurations

Verdict

Host Header Injection Fix provides a targeted solution for email header issues in older WordPress installations, but its relevance diminishes for users on newer versions.

From the developer

Jeff Starr's own description of Host Header Injection Fix, lightly tidied.

Important

As of WordPress 5.5, this plugin no longer is necessary to fix the host-header security issue reported in Ticket #25239 finally is fixed, and mentioned in this post WordPress 5.5 Beta 4. Thank You WordPress devs!

Is this plugin still useful?

Yes, it enables you to choose the “From”, “Name”, and “Return-Path” headers for all WP notification emails. And for versions of WordPress less than 5.5, this plugin continues to fix the host-header injection security issue.

Features

This simple plugin does three things:

  1. Sets custom From, Name, and Return-Path for WP notifications
  2. Fixes a security vulnerability in WordPress versions < 5.5
  3. Fixes a bug where invalid email addresses may be generated (in WordPress versions < 5.5)

Choose from the following options:

  • Use WordPress defaults (insecure for WP < 5.5)
  • Use “Email Address” from WP General Settings
  • Use a custom name and address

Plus there is an option to use the specified From address as the Return-Path header.

Why?

The security issue fixed by this plugin has been known about since way back in WordPress version 2.3. There has been some talk about fixing, but nothing has been implemented. While the issue does not affect all sites, it does affect a good percentage of them, including some of my own projects. So, not wanting to get hacked, I decided to write my own solution. Hopefully this issue gets fixed in a future version of WordPress, and this plugin will become unnecessary.

As a bonus, setting an explicit From address resolves a long-standing bug whereby an invalid email address is generated under the following conditions:

  • A “From” address is not set,
  • And the $_SERVER['SERVER_NAME'] is empty

So by explicitly setting a “From” address, we prevent this bug from happening.

Security Issue

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)