Arbitrary File Upload Vulnerability in Flex QR Code Generator Plugin for WordPress
CVE-2025-12673
9.8CRITICAL
What is CVE-2025-12673?
The Flex QR Code Generator plugin for WordPress has a serious vulnerability that allows unauthenticated attackers to upload arbitrary files due to inadequate file type validation in the update_qr_code() function. This flaw affects all versions up to and including 1.2.6, potentially enabling remote code execution on the affected site's server.
Affected Version(s)
Flex QR Code Generator * <= 1.2.6