← back
CVE-2026-16250

Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.