Impact
Unrestricted upload of files with dangerous types is possible in all releases of the Barcode Scanner with Inventory & Order Manager plugin up to version 1.6.7. The vulnerability allows an attacker to upload a web shell or other executable payload, giving them complete control over the hosting web server. This results in a full remote code execution threat with full confidentiality, integrity and availability impact on the affected site.
Affected Systems
The affected product is the WordPress Barcode Scanner with Inventory & Order Manager plugin developed by Dmitry V. (CEO of "UKR Solution"), versions from the earliest release through 1.6.7. WordPress sites that have installed or enabled this plugin are at risk; newer releases beyond 1.6.7 are not affected.
Risk and Exploitability
The CVSS score of 9.1 reflects a high-risk, remote exploitation scenario. Although the EPSS score is below 1%, indicating a low measured probability of exploitation, the absence of this CVE from the CISA KEV catalog does not reduce the urgency. Attackers can trigger the vulnerability over the internet by accessing the plugin’s file upload interface, and no special privileges are required beyond the ability to use the upload feature. Once an executable is uploaded, the attacker gains unrestricted code execution on the server.
OpenCVE Enrichment
EUVD