Impact
An unauthenticated user can insert arbitrary SQL statements through the subscriber field of the Barcode Scanner with Inventory & Order Manager plugin. The flaw stems from improper input validation (CWE-89) and allows attackers to read, modify, or delete inventory and order data, jeopardizing confidentiality, integrity, and availability of the platform's transactional records.
Affected Systems
The vulnerability affects the WordPress Barcode Scanner with Inventory & Order Manager plugin published by Dmitry V. Versions up to and including 1.13.1 are impacted. The recommendation is to upgrade to version 1.13.6 or later, which contains the remediation.
Risk and Exploitability
With a CVSS score of 8.5, the risk of exploitation is considered high. The EPSS score is not available, but the absence of a CISA KEV listing does not diminish the potential for abuse. Attackers could exploit the flaw by manipulating plugin input through the web interface, assuming the application does not guard against malformed SQL. Even without dedicated credentials, the plugin's inadequate sanitization enables a remote attacker to gain control over database contents.
OpenCVE Enrichment