CVE-2026-24545: WordPress QR Redirector plugin <= 2.0.3 - Broken Access Control vulnerability
Published May 25, 2026
·Updated
Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects QR Redirector: from n/a through 2.0.3.
Affected Software
1 affected component
Nikki Blight QR Redirector<=2.0.3
Remediation
Information
Update the WordPress QR Redirector Plugin to the latest available version (at least 2.0.4).
Event History
May 25, 2026
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-24545?
CVE-2026-24545 has a severity rating of medium with a score of 4.3.
2
What vulnerability does CVE-2026-24545 describe?
CVE-2026-24545 describes a Broken Access Control vulnerability in the WordPress QR Redirector plugin.
3
How do I fix CVE-2026-24545?
To fix CVE-2026-24545, update the WordPress QR Redirector plugin to version 2.0.4 or later.
4
What are the potential risks of CVE-2026-24545?
CVE-2026-24545 can result in unauthorized access due to incorrectly configured access control security levels.
5
Which versions of the software are affected by CVE-2026-24545?
CVE-2026-24545 affects the WordPress QR Redirector plugin from versions n/a up to 2.0.3.