CVE-2025-12673 | Flex QR Code Generator Plugin up to 1.2.6 on WordPress update_qr_code unrestricted upload (EUVD-2025-201530)
A vulnerability has been found in Flex QR Code Generator Plugin up to 1.2.6 on WordPress and classified as critical. Affected is the function update_qr_code. Performing manipulation results in unrestricted upload.
This vulnerability is known as CVE-2025-12673. Remote exploitation of the attack is possible. No exploit is available.