CVE-2026-16250
Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload
CVSS Score
9.8
EPSS Score
0.2%
EPSS Percentile
13th
The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.
| Vendor | unknown |
| Product | personal qr message |
| Published | Aug 3, 2026 |
| Last Updated | Aug 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown personal qr message
Be the first to know when new critical vulnerabilities affecting unknown personal qr message are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Personal QR Message
0 ≤ 1.0
References
Credits
João Ramos Maciel WPScan