QR Master
QR Master has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for QR Master has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by SOPROBRO. QR Master is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.1.42.
CVE-2025-32116QR Master <= 1.0.5 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

QR Master
Author
Studi7
QR Master generate shortcodes to include QR code in page or post. Get QR codes from Google API Charts and Php QR code. This plugin support two methods to getting QR: Value: get same QR whith fixed value Automatic: get random QR code for each visit in page or post. The shortcode form tool include: Form with parameters of Google API Charts, Form with parameters of Php QR Code API, CSS options and hide code information and credits. Foreground and background colours in QR Code (Php QR Code) All QR codes are generated in live. The Php QR Code API save some data in cache, please read FAQ. Available Languages English Català Español Serbian (thanks to Ogi Djuraskovic – First Site Guide) TO-DO Widget, save codes to database, insert shortcode assistant, customize css, value generator, QR-Server API
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C