A Cross-site Scripting (XSS) vulnerability exists in the QR Redirector plugin for WordPress, affecting versions from n/a through 2.0.5. This issue allows for Stored XSS, potentially enabling attackers to inject malicious scripts into web pages. The vulnerability's impact could include the injection of malicious scripts and potential impact on users interacting with affected web pages. Defenders should ass [truncated]
A Missing Authorization vulnerability in the QR Redirector WordPress plugin (versions through 2.0.3) allows attackers with low privileges to exploit incorrectly configured access control security levels. The vulnerability, classified as CWE-862, enables authenticated users to perform unauthorized actions due to broken access control mechanisms. The issue was published on May 25, 2026, and modified on May [truncated]