Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikki Blight QR Redirector qr-redirector allows Stored XSS.This issue affects QR Redirector: from n/a through 2.0.5.
Published: 2026-10-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS
Action: Patch Now
AI Analysis

Impact

The QR Redirector WordPress plugin handles user‑supplied data without proper output escaping, enabling stored cross‑site scripting. An attacker can inject malicious JavaScript into data fields that are later rendered on any page displaying the attribute, allowing the execution of arbitrary code in the browsers of visitors to the site. This leads to potential data theft, session hijacking, defacement or further propagation of malware. The weakness falls under CWE‑79.

Affected Systems

All instances of the Nikki Blight QR Redirector plugin with a version 2.0.5 or earlier are vulnerable. The plugin is available for WordPress sites and affects sites that have not yet upgraded to the fixed release, which starts at 2.0.6.

Risk and Exploitability

The CVSS base score of 6.5 indicates a moderate impact. The exploitability is limited to sites that allow privileged users to input data into the affected fields; a compromised or malicious administrator could store malicious code, or an attacker could target a site that allows unfiltered user input. Because the script is stored, any visitor to the affected pages will execute it, creating widespread impact once an entry point exists. The EPSS score is not reported, and the vulnerability is not currently listed in CISA’s KEV catalog, suggesting no known active exploitation at this time.

Generated by OpenCVE AI on October 5, 2026 at 10:44 UTC.

Remediation

Vendor Solution

Update the WordPress QR Redirector plugin to the latest available version (at least 2.0.6).


OpenCVE Recommended Actions

  • Update the QR Redirector plugin to version 2.0.6 or newer.
  • If an update is not immediately possible, disable or uninstall the QR Redirector plugin until the patch is applied.
  • Verify that the plugin’s database entries have been cleared of any suspicious content and conduct a full site security review.

Generated by OpenCVE AI on October 5, 2026 at 10:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikki Blight QR Redirector qr-redirector allows Stored XSS.This issue affects QR Redirector: from n/a through 2.0.5.
Title WordPress QR Redirector plugin <= 2.0.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T12:49:38.131Z

Reserved: 2026-10-03T00:17:03.678Z

Link: CVE-2026-105069

cve-icon Vulnrichment

Updated: 2026-10-05T12:48:43.709Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:11.423

Modified: 2026-10-05T13:16:52.320

Link: CVE-2026-105069

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:45:21Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')