Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bappa Mal QR Code for WooCommerce wc-qr-codes allows Reflected XSS.This issue affects QR Code for WooCommerce: from n/a through <= 1.2.0.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a reflected XSS flaw that, based on the description, likely allows attackers to inject arbitrary client‑side scripts into the output of the WordPress QR Code for WooCommerce plugin by supplying malicious input. Based on the description, the likely attack vector is an attacker who can lure a site visitor to a crafted URL or form submission that triggers execution of their code in the victim’s browser. This could lead to session hijacking, credential theft, defacement of the site, or redirection to phishing sites. Since the attack code runs in the context of the plugin’s page, the impact is primarily on the integrity and confidentiality of user data accessed by the victim’s browser.

Affected Systems

Affected installations are those running the Bappa Mal QR Code for WooCommerce WordPress plugin version 1.2.0 or earlier. The plugin is commonly used in WooCommerce stores to generate QR codes for products or checkout pages. Any site that has not upgraded beyond 1.2.0 remains vulnerable. Administrators should verify the installed version and apply the fix.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, and the EPSS score of less than 1% suggests low current exploitation probability, although the flaw has no known public exploit. Because it is a reflected XSS, the exploitation requires an attacker to entice a user to visit a malicious link or submit crafted data. The vulnerability is not listed in CISA’s KEV catalog, so it is not known as an actively exploited threat at present. Nonetheless, the simplicity of the attack path warrants prompt remediation.

Generated by OpenCVE AI on May 2, 2026 at 01:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the QR Code for WooCommerce plugin to the latest version that includes the XSS fix.
  • If an immediate upgrade cannot be deployed, apply a web‑application firewall rule or enable the platform’s built‑in XSS filter to block or escape the malicious input patterns that reach the plugin.
  • As a last resort, disable the QR generation functionality or remove the plugin entirely until a patched version is available.

Generated by OpenCVE AI on May 2, 2026 at 01:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11636 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bappa Mal QR Code for WooCommerce allows Reflected XSS. This issue affects QR Code for WooCommerce: from n/a through 1.2.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bappa Mal QR Code for WooCommerce allows Reflected XSS. This issue affects QR Code for WooCommerce: from n/a through 1.2.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bappa Mal QR Code for WooCommerce wc-qr-codes allows Reflected XSS.This issue affects QR Code for WooCommerce: from n/a through <= 1.2.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bappa Mal QR Code for WooCommerce allows Reflected XSS. This issue affects QR Code for WooCommerce: from n/a through 1.2.0.
Title WordPress QR Code for WooCommerce Plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:48.173Z

Reserved: 2025-02-21T16:45:40.233Z

Link: CVE-2025-27322

cve-icon Vulnrichment

Updated: 2025-04-17T17:44:45.341Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:37.373

Modified: 2026-06-17T09:03:23.980

Link: CVE-2025-27322

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T02:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')