Cross-site Scripting Vulnerability in QR Redirector by Nikki Blight
CVE-2026-105069
6.5MEDIUM
What is CVE-2026-105069?
A Cross-site Scripting (XSS) vulnerability exists in the QR Redirector plugin developed by Nikki Blight, which allows attackers to execute arbitrary JavaScript in the context of users accessing affected versions of the plugin. This vulnerability arises from improper input validation during web page generation, enabling the storage of malicious scripts that can compromise users’ sessions, steal sensitive data, or perform actions on behalf of the user without consent. This issue affects versions from n/a up to 2.0.5, emphasizing the need for timely updates and robust security measures.
Affected Version(s)
QR Redirector 0 <= 2.0.5