Impact
Missing Authorization in the Nikki Blight QR Redirector plugin allows an attacker to access functionality they should not be able to use. The weakness arises from incorrectly configured access control security levels that do not properly restrict privileged actions. This can enable an assailant to invoke or manipulate the plugin’s features without proper authentication, potentially exposing sensitive data or performing unwanted redirects.
Affected Systems
The vulnerability affects the Nikki Blight QR Redirector WordPress plugin versions up to and including 2.0.3. Any installation that has not upgraded beyond 2.0.3 remains susceptible. No other vendor or product versions are listed as affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. Exploit probability is unknown because EPSS is not provided, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the plugin’s exposed endpoints or configuration interfaces; an attacker could exploit the missing authorization through crafted requests or unauthorized access to the plugin’s management pages. No additional prerequisites beyond the plugin installation are stated, so the risk primarily hinges on whether the plugin is actively used and exposed.
OpenCVE Enrichment