PT-2026-33185 · WordPress · Barcode Scanner

Jude Nwadinobi

·

Published

2026-04-15

·

Updated

2026-04-16

·

CVE-2026-4880

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress versions prior to 1.11.1
Description Insecure token-based authentication allows unauthenticated attackers to escalate privileges to administrator. The issue stems from the plugin trusting a user-supplied Base64-encoded user ID within the token parameter to identify users. Additionally, valid authentication tokens are leaked through the 'barcodeScannerConfigs' action, and the 'setUserMeta' action lacks meta-key restrictions. An attacker can spoof an administrator user ID to leak their authentication token and subsequently use that token to update the wp capabilities meta of any user to gain full administrative access.
Recommendations Update to a version newer than 1.11.0.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2026-4880

Affected Products

Barcode Scanner