← WordPress Vulnerabilities
WordPress security by component

Personal QR Message

Personal QR Message (personal-qr-message) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 03, 2026; the highest published CVSS base score is 9.8.

Plugin slug: personal-qr-message

CVE-2026-16250: Personal QR Message permits unauthenticated PHP uploads

Personal QR Message through 1.0 exposes an unauthenticated upload handler that does not restrict file types. An unauthenticated attacker can upload a PHP file into a directly reachable location and request it to execute code as the web-server account. The CNA record does not disclose the handler, upload field, destination path or resulting URL pattern.

PublishedAug 03, 2026
Known safe version> 1.0
Published vulnerabilities for personal-qr-message
Safe version
Aug 03, 2026 CVE-2026-16250
Personal QR Message permits unauthenticated PHP uploads
Personal QR Message through 1.0 exposes an unauthenticated upload handler that does not restrict file types. An unauthenticated attacker can upload a PHP file into a directly reachable location and request it to execute code as the web-server account. The CNA record does not disclose the handler, upload field, destination path or resulting URL pattern.
> 1.0
CVE9.8
NVDPending