---
id: CVE-2025-10041
title: >-
  The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary
  file uploads due to missing file type validation in thesave_qr_code_to_db()
  function in all versions up to, and including, 1.2.5
summary: >-
  The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary
  file uploads due to missing file type validation in thesave_qr_code_to_db()
  function in all versions up to, and including, 1.2.5. This makes it possible
  for unaut…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
published: '2025-10-15'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10041'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/flex-qr-code-generator/tags/1.2.5/qr-code-generator.php#L208
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3379026%40flex-qr-code-generator&new=3379026%40flex-qr-code-generator&sfp_email=&sfph_mail=
    label: security@wordfence.com
  - url: 'https://wordpress.org/plugins/flex-qr-code-generator/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/40000879-a5ef-48f2-97e4-77d527259af0?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - exploit-available
epss: 0.0092
epssPercentile: 0.59052
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/Nxploited/CVE-2025-10041'
    - >-
      https://github.com/Kai-One001/WordPress-Flex-QR-Code-Generator---CVE-2025-10041
  checkedAt: '2026-10-08T12:40:22.925Z'
exploitAvailable: true
ingestedAt: '2026-10-08T11:31:27.418Z'
---

## Overview

The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in thesave_qr_code_to_db() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
