CVE-2026-16250

The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-03 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-16250

Mitre link : CVE-2026-16250

CVE.ORG link : CVE-2026-16250


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type