CVE Feed

    Dashboard / CVE / CVE-2021-24559

    CVE-2021-24559

    The Qyrr WordPress plugin before 0.7 does not escape the data-uri of the QR Code when outputting it in a src attribute, allowing for Cross-Site Scripting attacks. Furthermore, the data_uri_to_meta AJAX action, available to all authenticated users, only had a CSRF check in place, with the nonce available to users with a role as low as Contributor allowing any user with such role (and above) to set a malicious data-uri in arbitrary QR Code posts, leading to a Stored Cross-Site Scripting issue.

    Published:Jan 16, 2024
    Last Modified:Jun 20, 2025
    EPS:Jan 16, 2024
    EPSS Score:0.00294
    CVSS Score:5.4

    Affected Products

    Vendor
    Patrickposner
    Product
    Qyrr

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High