WordPress security by component
Personal QR Message
Personal QR Message (personal-qr-message) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 03, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
personal-qr-messageLatest vulnerability
CVE-2026-16250: Personal QR Message permits unauthenticated PHP uploads
Personal QR Message through 1.0 exposes an unauthenticated upload handler that does not restrict file types. An unauthenticated attacker can upload a PHP file into a directly reachable location and request it to execute code as the web-server account. The CNA record does not disclose the handler, upload field, destination path or resulting URL pattern.
| Safe version |
|
||
|---|---|---|---|
| Aug 03, 2026 |
CVE-2026-16250
Personal QR Message permits unauthenticated PHP uploads
Personal QR Message through 1.0 exposes an unauthenticated upload handler that does not restrict file types. An unauthenticated attacker can upload a PHP file into a directly reachable location and request it to execute code as the web-server account. The CNA record does not disclose the handler, upload field, destination path or resulting URL pattern.
|
> 1.0 |
CVE9.8
NVDPending
|