CVE-2026-24545: WordPress QR Redirector plugin <= 2.0.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects QR Redirector: from n/a through 2.0.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress QR Redirector Pluginto a version that resolves this vulnerability.Fixed in 2.0.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24545?
CVE-2026-24545 has a severity rating of medium with a score of 4.3.
What vulnerability does CVE-2026-24545 describe?
CVE-2026-24545 describes a Broken Access Control vulnerability in the WordPress QR Redirector plugin.
How do I fix CVE-2026-24545?
To fix CVE-2026-24545, update the WordPress QR Redirector plugin to version 2.0.4 or later.
What are the potential risks of CVE-2026-24545?
CVE-2026-24545 can result in unauthorized access due to incorrectly configured access control security levels.
Which versions of the software are affected by CVE-2026-24545?
CVE-2026-24545 affects the WordPress QR Redirector plugin from versions n/a up to 2.0.3.