cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forqr-redirector qr-redirector

Direction: ascending
Jun 06, 2024

QR Redirector # CVE-2021-24854

CVE, Research URL

CVE-2021-24854

Application

QR Redirector

Date
Nov 17, 2021
Research Description
The QR Redirector WordPress plugin before 1.6.1 does not sanitise and escape some of the QR Redirect fields, which could allow users with a role as low as Contributor perform Stored Cross-Site Scripting attacks.
Affected versions
max 1.6.1.
Status
vulnerable

QR Redirector # CVE-2021-24853

CVE, Research URL

CVE-2021-24853

Application

QR Redirector

Date
Nov 17, 2021
Research Description
The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR Redirects
Affected versions
max 1.6.1.
Status
vulnerable
May 27, 2026

QR Redirector # CVE-2026-24545

CVE, Research URL

CVE-2026-24545

Application

QR Redirector

Date
May 26, 2026
Research Description
Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects QR Redirector: from n/a through 2.0.3.
Affected versions
max 2.0.4.
Status
vulnerable