PT-2026-33185 · WordPress · Barcode Scanner
Jude Nwadinobi
·
Published
2026-04-15
·
Updated
2026-04-16
·
CVE-2026-4880
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress versions prior to 1.11.1
Description
Insecure token-based authentication allows unauthenticated attackers to escalate privileges to administrator. The issue stems from the plugin trusting a user-supplied Base64-encoded user ID within the
token parameter to identify users. Additionally, valid authentication tokens are leaked through the 'barcodeScannerConfigs' action, and the 'setUserMeta' action lacks meta-key restrictions. An attacker can spoof an administrator user ID to leak their authentication token and subsequently use that token to update the wp capabilities meta of any user to gain full administrative access.Recommendations
Update to a version newer than 1.11.0.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Barcode Scanner