CyberRota Analysis
AI-GeneratedThe Personal QR Message WordPress plugin allows unauthenticated users to upload arbitrary executable PHP files due to a lack of file type restrictions, which can lead to remote code execution on affected WordPress sites. This vulnerability poses a significant risk to site integrity and security, making it essential for WordPress administrators using this plugin to prioritize immediate updates or remediation. All users of the plugin should assess their exposure and take action to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.