LiveActive security incident?Get immediate response
CVE Record

CVE-2026-16250: Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload

The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.

CriticalCVSS 9.8Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

An internet attacker can reportedly upload a malicious PHP file through the Personal QR Message WordPress plugin without logging in. Because the uploaded file is directly reachable, the attacker could run code on the server, steal or alter data, disrupt the site, and potentially use the compromised host for further attacks.

Executive priority

Treat confirmed installations as an immediate remediation and compromise-assessment priority. The reported flaw permits full server-side code execution from the internet without credentials. Rapid containment is warranted even without evidence of active exploitation because exploitation conditions are unusually favorable and consequences can include total website and data compromise.

Technical view

Personal QR Message through version 1.0 reportedly exposes an unauthenticated upload handler that does not restrict uploaded file types. An attacker can upload an executable PHP file and access it directly, producing remote code execution. The issue is classified as CWE-434 and scored CVSS 3.1 9.8 because exploitation requires no privileges or user interaction.

Likely exposure

WordPress sites running Personal QR Message version 1.0 or earlier are potentially exposed when the vulnerable upload handler is reachable. The supplied affected-version metadata is inconsistent, listing version “0” while the title and description state through 1.0; inventories should conservatively investigate all installed versions.

Exploitation context

The vulnerability is remotely reachable, low complexity, unauthenticated, and requires no user interaction. The WPScan reference is tagged for exploit information, but the supplied evidence does not establish active exploitation. CVE-2026-16250 is not identified as being in CISA KEV within this source bundle.

Researcher notes

The central claim is an unrestricted unauthenticated file upload leading to directly reachable PHP execution. Public source coverage in the supplied bundle is limited, and no fixed version, vendor patch, handler path, exploitation telemetry, or official mitigation is provided. Avoid treating the WPScan “exploit” reference tag alone as evidence of exploitation in the wild.

Mitigation direction

  • Identify and prioritize every WordPress site running Personal QR Message.
  • Disable or remove the plugin until authoritative vendor remediation guidance is available.
  • Check vendor or WordPress ecosystem guidance for a fixed release or official mitigation.
  • Restrict public access to the affected functionality where removal is temporarily impossible.
  • Investigate exposed sites for unauthorized uploads and signs of server compromise.

Validation and detection

  • Confirm the installed plugin version on every WordPress instance.
  • Verify the plugin is disabled, removed, or updated according to authoritative guidance.
  • Review upload locations for unexpected PHP or other executable files.
  • Review web and application logs for suspicious unauthenticated upload activity.
  • Confirm executable files cannot be served from applicable upload directories.
  • Escalate affected hosts for incident response if suspicious files or activity are found.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-434: File access and web shell behavior lookup

File traversal and upload weaknesses can lead teams to review file, web shell, execution, and collection telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
description · low confidence lookup

File access behavior lookup

The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-16250 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
2Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.8CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H3.95.9CISA-ADP

Vulnerability scoring details

Base CVSS 3.1 score

9.8Critical
CVSS 3.1 vector shape for CVE-2026-16250Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
cvssV3_1other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
UnknownPersonal QR Message0unknown
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-434 · source CWE mapping

Unrestricted Upload of File with Dangerous Type

Unrestricted Upload of File with Dangerous Type represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.