SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16250

CRITICAL · CVSS 9.8 EPSS 0.51% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The Personal QR Message WordPress plugin allows unauthenticated users to upload arbitrary executable PHP files due to a lack of file type restrictions, which can lead to remote code execution on affected WordPress sites. This vulnerability poses a significant risk to site integrity and security, making it essential for WordPress administrators using this plugin to prioritize immediate updates or remediation. All users of the plugin should assess their exposure and take action to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16250
Severity
CRITICAL
CVSS
9.8
EPSS
0.51%
WordPress

Original NVD Description

The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.