PT-2024-18213 · WordPress · Print Labels With Barcodes
Lucio Sá
·
Published
2024-05-02
·
Updated
2025-06-05
·
CVE-2024-1677
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Print Labels with Barcodes plugin for WordPress versions up to, and including, 3.4.6
Description
The issue allows for unauthorized access, modification, and loss of data due to an improper capability check on 42 separate AJAX functions. This enables authenticated attackers with subscriber access or higher to fully control the plugin, including modifying settings and profiles, and creating, editing, retrieving, and deleting templates and barcodes.
Recommendations
For versions up to, and including, 3.4.6, update the plugin to a version higher than 3.4.6 to resolve the issue.
As a temporary workaround, consider restricting access to the plugin's AJAX functions until a patch is available.
Restrict subscriber access and above to minimize the risk of exploitation.
Fix
Incorrect Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Print Labels With Barcodes