CVE-2021-24854
The QR Redirector WordPress plugin before 1.6.1 does not sanitise and escape some of the QR Redirect fields, which could allow users with a role as low as Contributor perform Stored Cross-Site Scripting attacks.
- Affected products
- Qr Redirector
- Qr Redirector Project Qr Redirector
- < 1.6.1
- Fix
- Available
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.6% (48th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2021-11-17
CVE-2021-24854 at NVD
1 known exploit for CVE-2021-24854
Proof-of-concept code and exploit modules indexed by Sploitus