PT-2026-67099 · WordPress · Personal Qr Message

CVE-2026-16250

·

Published

2026-08-03

·

Updated

2026-08-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Personal QR Message WordPress plugin versions prior to 1.1
Description An unauthenticated handler fails to restrict uploaded file types, enabling unauthenticated users to upload arbitrary executable PHP files. Since these files are directly reachable, this can lead to remote code execution (RCE), which is the ability of an attacker to execute arbitrary commands on the host machine.
Recommendations Update the Personal QR Message WordPress plugin to a version newer than 1.0.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16250

Affected Products

Personal Qr Message