QR Redirector <= 1.5 - Cross-Site Request Forgery

2021-10-18 00:00
apple502j

Strategic Overview

Status
Patched in 1.6
Affected PluginQR Redirector
Affected Version< 1.6
CVSS4.3Medium
CVECVE-2021-24853
View all QR Redirector vulnerabilities

Vulnerability Overview

The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR Redirects

Technical Analysis

REMEDIATION: Update to version 1.6, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C