ZeroHour

CVE-2021-24853

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p38
Published
()
Modified
Description

The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR Redirects

Vendors
qr redirector project
Products
qr redirector
Ecosystems
WordPress
Weakness
CWE-284, CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.