Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw in the WordPress QR Code Generator plugin caused by improper neutralization of input during page generation. An attacker who can supply malicious input through the plugin’s interface can cause arbitrary JavaScript to execute in the context of any user who loads the affected page. This could enable session hijacking, cookie theft, or defacement, leveraging the plugin’s ability to render QR codes within the site’s front‑end.
Affected Systems
The flaw affects the mobstac QR Code Generator plugin for WordPress, version 1.2.6 and earlier. Site owners running this plugin on any WordPress installation are at risk until the plugin is updated beyond 1.2.6.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity; however, the EPSS score of less than 1% and absence from the CISA KEV list suggest that widespread exploitation is currently unlikely. The most probable attack vector is through the plugin’s UI or URL parameters that embed user data into the page, allowing an attacker to craft a payload that executes when the page is rendered in the victim’s browser. While the vulnerability is client‑side, any authenticated or unauthenticated user who views the vulnerable page can be affected.
OpenCVE Enrichment
EUVD