CVE-2026-16250: Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload
The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.
Security readout for executives and security teams
Plain-English summary
An internet attacker can reportedly upload a malicious PHP file through the Personal QR Message WordPress plugin without logging in. Because the uploaded file is directly reachable, the attacker could run code on the server, steal or alter data, disrupt the site, and potentially use the compromised host for further attacks.
Executive priority
Treat confirmed installations as an immediate remediation and compromise-assessment priority. The reported flaw permits full server-side code execution from the internet without credentials. Rapid containment is warranted even without evidence of active exploitation because exploitation conditions are unusually favorable and consequences can include total website and data compromise.
Technical view
Personal QR Message through version 1.0 reportedly exposes an unauthenticated upload handler that does not restrict uploaded file types. An attacker can upload an executable PHP file and access it directly, producing remote code execution. The issue is classified as CWE-434 and scored CVSS 3.1 9.8 because exploitation requires no privileges or user interaction.
Likely exposure
WordPress sites running Personal QR Message version 1.0 or earlier are potentially exposed when the vulnerable upload handler is reachable. The supplied affected-version metadata is inconsistent, listing version “0” while the title and description state through 1.0; inventories should conservatively investigate all installed versions.
Exploitation context
The vulnerability is remotely reachable, low complexity, unauthenticated, and requires no user interaction. The WPScan reference is tagged for exploit information, but the supplied evidence does not establish active exploitation. CVE-2026-16250 is not identified as being in CISA KEV within this source bundle.
Researcher notes
The central claim is an unrestricted unauthenticated file upload leading to directly reachable PHP execution. Public source coverage in the supplied bundle is limited, and no fixed version, vendor patch, handler path, exploitation telemetry, or official mitigation is provided. Avoid treating the WPScan “exploit” reference tag alone as evidence of exploitation in the wild.
Mitigation direction
Identify and prioritize every WordPress site running Personal QR Message.
Disable or remove the plugin until authoritative vendor remediation guidance is available.
Check vendor or WordPress ecosystem guidance for a fixed release or official mitigation.
Restrict public access to the affected functionality where removal is temporarily impossible.
Investigate exposed sites for unauthorized uploads and signs of server compromise.
Validation and detection
Confirm the installed plugin version on every WordPress instance.
Verify the plugin is disabled, removed, or updated according to authoritative guidance.
Review upload locations for unexpected PHP or other executable files.
Review web and application logs for suspicious unauthenticated upload activity.
Confirm executable files cannot be served from applicable upload directories.
Escalate affected hosts for incident response if suspicious files or activity are found.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-434: File access and web shell behavior lookup
File traversal and upload weaknesses can lead teams to review file, web shell, execution, and collection telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
2Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-434 · source CWE mapping
Unrestricted Upload of File with Dangerous Type
Unrestricted Upload of File with Dangerous Type represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.