CVE-2025-10041 | Flex QR Code Generator Plugin up to 1.2.5 on WordPress thesave_qr_code_to_db unrestricted upload
A vulnerability identified as critical has been detected in Flex QR Code Generator Plugin up to 1.2.5 on WordPress. Impacted is the function thesave_qr_code_to_db. Performing manipulation results in unrestricted upload.
This vulnerability is known as CVE-2025-10041. Remote exploitation of the attack is possible. No exploit is available.