PT-2021-16335 · WordPress · Qr Redirector

Apple502J

·

Published

2021-11-17

·

Updated

2021-11-19

·

CVE-2021-24853

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: QR Redirector WordPress plugin versions prior to 1.6
Description: The issue concerns a lack of capability and CSRF checks when saving bulk QR Redirector settings via the "qr save bulk" AJAX action. This could allow any authenticated user, such as a subscriber, to change the redirect response status code of arbitrary QR Redirects.
Recommendations: For versions prior to 1.6, update to version 1.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the "qr save bulk" AJAX action to prevent unauthorized changes to QR Redirect settings.

Exploit

Fix

Improper Access Control

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24853

Affected Products

Qr Redirector