Impact
The vulnerability is a missing authorization flaw that allows an attacker to generate price tags, product labels, or order labels without proper authentication or role verification. By exploiting the flaw, an unauthorized user could create or modify labels that may expose sensitive product information or alter order data, compromising confidentiality and integrity of the shop’s inventory and documentation. The weakness is an access control issue and does not provide arbitrary code execution or denial of service.
Affected Systems
The affected software is the WooCommerce plugin a4-barcode-generator from UKR Solution, available in versions up to and including 3.4.10. This includes the customer‑facing feature set that creates barcoded labels for products and orders.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% points to a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, and no widely known exploits exist. Based on the description, the likely attack vector is via standard HTTP requests to the label‑generation endpoint, potentially without requiring any user authentication if the plugin does not enforce role checks.
OpenCVE Enrichment
EUVD