Cross-site Scripting Vulnerability in QR Redirector by Nikki Blight
CVE-2026-105069

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 October 2026

What is CVE-2026-105069?

A Cross-site Scripting (XSS) vulnerability exists in the QR Redirector plugin developed by Nikki Blight, which allows attackers to execute arbitrary JavaScript in the context of users accessing affected versions of the plugin. This vulnerability arises from improper input validation during web page generation, enabling the storage of malicious scripts that can compromise users’ sessions, steal sensitive data, or perform actions on behalf of the user without consent. This issue affects versions from n/a up to 2.0.5, emphasizing the need for timely updates and robust security measures.

Affected Version(s)

QR Redirector 0 <= 2.0.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.