Impact
The QR Redirector WordPress plugin handles user‑supplied data without proper output escaping, enabling stored cross‑site scripting. An attacker can inject malicious JavaScript into data fields that are later rendered on any page displaying the attribute, allowing the execution of arbitrary code in the browsers of visitors to the site. This leads to potential data theft, session hijacking, defacement or further propagation of malware. The weakness falls under CWE‑79.
Affected Systems
All instances of the Nikki Blight QR Redirector plugin with a version 2.0.5 or earlier are vulnerable. The plugin is available for WordPress sites and affects sites that have not yet upgraded to the fixed release, which starts at 2.0.6.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate impact. The exploitability is limited to sites that allow privileged users to input data into the affected fields; a compromised or malicious administrator could store malicious code, or an attacker could target a site that allows unfiltered user input. Because the script is stored, any visitor to the affected pages will execute it, creating widespread impact once an entry point exists. The EPSS score is not reported, and the vulnerability is not currently listed in CISA’s KEV catalog, suggesting no known active exploitation at this time.
OpenCVE Enrichment