plugin

Qr Code Tag For Wc From Goaskle Com Vulnerabilities

4 known security issues reported for the Qr Code Tag For Wc From Goaskle Com WordPress plugin. Most recent disclosed Jan 7, 2026.

2 medium

Running Qr Code Tag For Wc From Goaskle Com on your site? Check whether your installed version is affected.

Scan your site free

QR Code for WooCommerce order emails, PDF invoices, packing slips [qr-code-tag-for-wc-from-goaskle-com] <= 1.9.42 (unfixed)

unknown

[en] The QR Code for WooCommerce order emails, PDF invoices, packing slips plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 1.9.42 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possi...

Affected:
up to 1.9.42
Fix:
No patched version reported
Disclosed:
Jan 7, 2026

CVE-2025-14626 on NVD →

QR Code for WooCommerce order emails, PDF invoices, packing slips <= 1.9.42 - Authenticated (Contributor+) Cross-Site Scripting via Shortcode Attributes

medium

The QR Code for WooCommerce order emails, PDF invoices, packing slips plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 1.9.42 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f...

CVSS:
6.4
Affected:
up to 1.9.42
Fix:
No patched version reported
Disclosed:
Jan 6, 2026

CVE-2025-14626 on NVD →

QR Code Tag for WC order emails <= 1.9.36 - Cross-Site Request Forgery

medium

The QR Code Tag for WC order emails, POS receipt emails, PDF invoices, PDF packing slips, Blog posts, Custom post types and Pages (from goaskle.com) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.36. This is due to missing or incorrect nonce validation on a fu...

CVSS:
4.3
Affected:
up to 1.9.36
Fix:
No patched version reported
Disclosed:
Apr 4, 2025

CVE-2025-32268 on NVD →

QR Code for WooCommerce order emails, PDF invoices, packing slips [qr-code-tag-for-wc-from-goaskle-com] <= 1.9.36 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in www.15.to QR Code Tag for WC allows Cross Site Request Forgery. This issue affects QR Code Tag for WC: from n/a through 1.9.36.

Affected:
up to 1.9.36
Fix:
No patched version reported
Disclosed:
Apr 4, 2025

CVE-2025-32268 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database