Executive brief
QR Redirector is a WordPress plugin used to manage and redirect QR code links. A security flaw in the plugin allows logged-in users with low-level permissions to perform actions they should not be authorized to do. This could lead to unauthorized changes to the plugin's settings or redirected links, potentially impacting how visitors are routed.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Nikki Blight QR Redirector plugin for WordPress through version 2.0.3. The flaw stems from a failure to properly validate user permissions or security levels on certain functions, allowing an authenticated attacker with Subscriber-level privileges to execute actions intended for higher-privileged users. This broken access control can result in unauthorized modifications to plugin data. The issue is resolved in version 2.0.4.
Affected products
- Nikki Blight QR Redirector <= 2.0.3
Timeline
- 2025-12-25: other: Reported by Legion Hunter
- 2026-05-25: patched: Version 2.0.4 released
- 2026-05-25: disclosed: Published by Patchstack