Input validation vulnerability in Kaya QR Code Generator 1.5.2

The Kaya QR Code Generator plugin for WordPress is vulnerable to malicious code being inserted into webpages. This code can be used to harm visitors of the website when they access the page with the malicious code. Versions up to and including 1.5.2 of the plugin are affected due to lack of proper input checks and output escaping. Attackers with contributor-level permissions or higher can take advantage of this vulnerability to inject arbitrary web scripts into pages, which will then be executed by every user who visits those pages.

Detected in:

Kaya QR Code Generator fixed vulnerable versions: >= * <= 1.5.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.