Impact
The Flex QR Code Generator plugin for WordPress contains an improper neutralization of input during page generation that allows an attacker to inject malicious JavaScript into the web page. This DOM‑based cross‑site scripting flaw can cause arbitrary code execution in the context of a victim’s browser session, potentially leading to session hijacking, credential theft, or defacement. The vulnerability is identified as CWE‑79.
Affected Systems
The flaw affects the Devsbrain Flex QR Code Generator plugin version 1.2.10 and earlier. Any WordPress site that has installed these plugin versions is at risk.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is reported as less than 1 %, implying a very low likelihood that attackers have discovered or are actively exploiting this flaw. It is not listed in the CISA KEV catalog. The attack vector is presumably by delivering a crafted QR code or modifying plugin parameters that a victim interacts with, a scenario inferred from the description of a DOM‑based flaw. No network‑level prerequisites are required; the vulnerability is exploitable via a browser targeting the site.
OpenCVE Enrichment