What is CVE-2026-16250?
The Personal QR Message plugin for WordPress up to version 1.0 lacks file type restrictions, allowing unauthenticated attackers to upload arbitrary PHP files. This leads to remote code execution (RCE) on the server. Immediate plugin update or removal is recommended.
Azərbaycanca: WordPress üçün "Personal QR Message" plaqininin 1.0 versiyasına qədər olanlarında fayl yükləmə məhdudiyyətinin olmaması autentifikasiyasız istifadəçilərə ixtiyari PHP faylları yükləməyə imkan verir. Bu, serverdə uzaqdan kod icrasına (RCE) səbəb olur. Təcili olaraq plaqini yeniləmək və ya silmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
What does the CVE-2026-16250 vulnerability in the 'Personal QR Message' plugin for WordPress lead to?
This vulnerability allows unauthenticated attackers to upload arbitrary PHP files, leading to remote code execution (RCE) on the server.
What is the recommended action to protect against CVE-2026-16250?
Immediate plugin update or removal is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.