Impact
Cross‑Site Request Forgery (CWE‑352) exists in the QR Code Tag for WC WordPress plugin up to version 1.9.42. The flaw allows an attacker to forge a request that is processed by the plugin with the victim’s authenticated session, enabling unauthorized changes to the plugin’s configuration. The vulnerability can lead to configuration corruption, potential compromise of site functionality, and may expose sensitive data if configuration values control sensitive behavior.
Affected Systems
The affected product is QR Code Tag for WC from www.15.to. All releases up to and including 1.9.42 are vulnerable; newer releases are not documented as affected.
Risk and Exploitability
The CVSS score is 4.3, indicating moderate risk, and the EPSS score is below 1 %, showing a low likelihood of exploitation as of the current data. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the flaw by delivering a crafted link or form to a logged‑in user, exploiting the absence of CSRF protection when changing settings. No special privileges are required beyond a valid user session.
OpenCVE Enrichment
EUVD