Description
Subscriber SQL Injection in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.
Published: 2026-10-10
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Data manipulation
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated user can insert arbitrary SQL statements through the subscriber field of the Barcode Scanner with Inventory & Order Manager plugin. The flaw stems from improper input validation (CWE-89) and allows attackers to read, modify, or delete inventory and order data, jeopardizing confidentiality, integrity, and availability of the platform's transactional records.

Affected Systems

The vulnerability affects the WordPress Barcode Scanner with Inventory & Order Manager plugin published by Dmitry V. Versions up to and including 1.13.1 are impacted. The recommendation is to upgrade to version 1.13.6 or later, which contains the remediation.

Risk and Exploitability

With a CVSS score of 8.5, the risk of exploitation is considered high. The EPSS score is not available, but the absence of a CISA KEV listing does not diminish the potential for abuse. Attackers could exploit the flaw by manipulating plugin input through the web interface, assuming the application does not guard against malformed SQL. Even without dedicated credentials, the plugin's inadequate sanitization enables a remote attacker to gain control over database contents.

Generated by OpenCVE AI on October 10, 2026 at 21:29 UTC.

Remediation

Vendor Solution

Update the WordPress Barcode Scanner with Inventory & Order Manager plugin to the latest available version (at least 1.13.6).


OpenCVE Recommended Actions

  • Update the plugin to version 1.13.6 or newer.
  • If an update cannot be applied immediately, disable or remove the Barcode Scanner with Inventory & Order Manager plugin to block the vulnerability.
  • Enforce strict access controls on the plugin’s configuration settings, ensuring only administrators with strong authentication can make changes.

Generated by OpenCVE AI on October 10, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Subscriber SQL Injection in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.
Title WordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.13.1 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T19:36:00.956Z

Reserved: 2026-07-13T06:15:14.350Z

Link: CVE-2026-62117

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T20:16:44.060

Modified: 2026-10-10T20:16:44.060

Link: CVE-2026-62117

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T21:30:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')