Yes, it is a strange case, because as you mention, the upgrade-insecure-request option is disabled, yet it is the only one that appears in the CSP inspection. There is no CSP declared in the .htaccess and the only plugin I have tried to test on the site is this one. Additionally, it does not have any cache plugin. I am trying to purge the cache from the server.