Vulnerabilities and security researches forqr-redirector qr-redirector
Direction: ascendingJun 06, 2024
QR Redirector # CVE-2021-24854
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 17, 2021
- Research Description
- The QR Redirector WordPress plugin before 1.6.1 does not sanitise and escape some of the QR Redirect fields, which could allow users with a role as low as Contributor perform Stored Cross-Site Scripting attacks.
- Affected versions
-
max 1.6.1.
- Status
-
vulnerable
QR Redirector # CVE-2021-24853
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 17, 2021
- Research Description
- The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR Redirects
- Affected versions
-
max 1.6.1.
- Status
-
vulnerable
May 27, 2026
QR Redirector # CVE-2026-24545
- CVE, Research URL
- Home page URL
- Application
- Date
- May 26, 2026
- Research Description
- Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects QR Redirector: from n/a through 2.0.3.
- Affected versions
-
max 2.0.4.
- Status
-
vulnerable