Impact
Improper neutralization of user input during web page generation allows the Studi7 QR Master plugin to reflect attackers’ JavaScript in a victim’s browser. When a malicious user visits a crafted URL or enters malicious data, the script is executed with the site’s privileges, enabling cookie theft, session hijacking, defacement, or the launch of further attacks while the user is authenticated.
Affected Systems
Any WordPress site that has the QR Master plugin installed in a version up to and including 1.0.5 is vulnerable. The flaw resides solely in the plugin, so all affected sites regardless of their WordPress core version are at risk.
Risk and Exploitability
The CVSS score of 7.1 designates this as a high‑severity vulnerability. The EPSS score of less than 1 % indicates a low current exploitation probability, and the issue is not listed in the CISA KEV catalog. Based on the description, the attack vector is a crafted URL or input field that sends the payload to the plugin; no authentication or privileged access is required, so any visitor can trigger the reflected script.
OpenCVE Enrichment
EUVD