Flex QR Code Generator Plugin Vulnerability

CRITICAL (9.8)

Threat Intelligence

⚠️ CRITICAL GAP - Exploits exist but no detection available
EPSS Score: 0.18% chance of exploitation (percentile: 40%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: GitHub PoC

How we test →

What is it?

The Flex QR Code Generator plugin is a WordPress plugin used to generate QR codes. This vulnerability allows attackers to upload arbitrary files on the affected site's server, which may lead to remote code execution.

Am I affected?

You're affected if you use Flex QR Code Generator. Specific version info not stated in the advisory.

How to fix

See the GitHub issue/commit: https://github.com/d0n601/CVE-2025-12673 As immediate mitigation: restrict network access to affected systems if possible.