🔐 CVE Alert

CVE-2026-16250

CRITICAL 9.8

Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload

CVSS Score
9.8
EPSS Score
0.2%
EPSS Percentile
13th

The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.

Vendor unknown
Product personal qr message
Published Aug 3, 2026
Last Updated Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for unknown personal qr message

Be the first to know when new critical vulnerabilities affecting unknown personal qr message are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Personal QR Message
0 ≤ 1.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/05bd2683-ef3b-4816-a323-12d5e943612a/

Credits

João Ramos Maciel WPScan