← back
CVE-2021-24853

QR Redirector < 1.6 - Subscriber+ Arbitrary QR Redirect Response Status Update

EPSS 0.4%CWE-284
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
17 Nov 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR Redirects
Affected products
Unknown · QR Redirector