Impact
The vulnerability allows an attacker to inject a malicious payload into data stored by the Vasaio QR Code plugin, which is then rendered to users who view the affected content. This results in stored cross‑site scripting. The flaw is recorded as a CSRF issue (CWE‑352).
Affected Systems
The issue affects the Vasaio QR Code plugin developed by Olar Marius. All installations running version 1.2.5 or earlier are potentially vulnerable. No additional vendor or product variants are listed.
Risk and Exploitability
The CVSS score of 7.1 classifies the flaw as high severity. The EPSS score of less than 1% indicates a low probability of exploitation in the wild at present. The vulnerability is not currently identified in the CISA KEV catalog. Based on the description, it is inferred that the attack vector involves a CSRF mechanism, requiring an authenticated user to submit a crafted request that results in persistent XSS affecting all users who view the content.
OpenCVE Enrichment
EUVD