Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Devsbrain Flex QR Code Generator flex-qr-code-generator allows DOM-Based XSS.This issue affects Flex QR Code Generator: from n/a through <= 1.2.10.
Published: 2026-01-23
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: DOM‑based Cross‑Site Scripting that can execute code in visitors’ browsers
Action: Apply Patch
AI Analysis

Impact

The Flex QR Code Generator plugin for WordPress contains an improper neutralization of input during page generation that allows an attacker to inject malicious JavaScript into the web page. This DOM‑based cross‑site scripting flaw can cause arbitrary code execution in the context of a victim’s browser session, potentially leading to session hijacking, credential theft, or defacement. The vulnerability is identified as CWE‑79.

Affected Systems

The flaw affects the Devsbrain Flex QR Code Generator plugin version 1.2.10 and earlier. Any WordPress site that has installed these plugin versions is at risk.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The EPSS score is reported as less than 1 %, implying a very low likelihood that attackers have discovered or are actively exploiting this flaw. It is not listed in the CISA KEV catalog. The attack vector is presumably by delivering a crafted QR code or modifying plugin parameters that a victim interacts with, a scenario inferred from the description of a DOM‑based flaw. No network‑level prerequisites are required; the vulnerability is exploitable via a browser targeting the site.

Generated by OpenCVE AI on April 16, 2026 at 01:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Flex QR Code Generator plugin to version 1.2.11 or later, which removes the XSS vulnerability.
  • If an upgrade is not immediately feasible, temporarily disable or delete the plugin to eliminate the attack surface.
  • Consider deploying a web application firewall or Content Security Policy that blocks inline scripts to mitigate potential exploitation while awaiting a patch.

Generated by OpenCVE AI on April 16, 2026 at 01:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Devsbrain Flex QR Code Generator flex-qr-code-generator allows DOM-Based XSS.This issue affects Flex QR Code Generator: from n/a through <= 1.2.8. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Devsbrain Flex QR Code Generator flex-qr-code-generator allows DOM-Based XSS.This issue affects Flex QR Code Generator: from n/a through <= 1.2.10.
Title WordPress Flex QR Code Generator plugin <= 1.2.8 - Cross Site Scripting (XSS) vulnerability WordPress Flex QR Code Generator plugin <= 1.2.10 - Cross Site Scripting (XSS) vulnerability

Mon, 26 Jan 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 23 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Devsbrain Flex QR Code Generator flex-qr-code-generator allows DOM-Based XSS.This issue affects Flex QR Code Generator: from n/a through <= 1.2.8.
Title WordPress Flex QR Code Generator plugin <= 1.2.8 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:14:25.803Z

Reserved: 2026-01-23T12:32:24.371Z

Link: CVE-2026-24614

cve-icon Vulnrichment

Updated: 2026-01-23T17:48:31.248Z

cve-icon NVD

Status : Deferred

Published: 2026-01-23T15:16:20.287

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-24614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T01:45:20Z

Weaknesses