Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8epss 0.5%
exploitation probability
0.5%top 58% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · Personal QR Messagepublic PoCs found — 1
cve_referencewpscan.com/vulnerability/05bd2683-ef3b-4816-a323-12d5e943612a/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.