PT-2024-18213 · WordPress · Print Labels With Barcodes

Lucio Sá

·

Published

2024-05-02

·

Updated

2025-06-05

·

CVE-2024-1677

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Print Labels with Barcodes plugin for WordPress versions up to, and including, 3.4.6
Description The issue allows for unauthorized access, modification, and loss of data due to an improper capability check on 42 separate AJAX functions. This enables authenticated attackers with subscriber access or higher to fully control the plugin, including modifying settings and profiles, and creating, editing, retrieving, and deleting templates and barcodes.
Recommendations For versions up to, and including, 3.4.6, update the plugin to a version higher than 3.4.6 to resolve the issue. As a temporary workaround, consider restricting access to the plugin's AJAX functions until a patch is available. Restrict subscriber access and above to minimize the risk of exploitation.

Fix

Incorrect Authorization

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-1677

Affected Products

Print Labels With Barcodes