CVE-2026-16250 PUBLISHED

Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload

Assigner: WPScan
Reserved: 20.07.2026 Published: 03.08.2026 Updated: 03.08.2026

The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.

Product Status

Vendor Unknown
Product Personal QR Message
Versions Default: unknown
  • affected from 0 to 1.0 (incl.)

Credits

  • João Ramos Maciel finder
  • WPScan coordinator

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE