Impact
The vulnerability is an unauthenticated Broken Access Control that allows attackers to perform privileged actions on the WordPress Barcode Scanner with Inventory & Order Manager plugin. This flaw is classified as CWE-862, meaning that users without proper authorization can gain unauthorized capabilities, potentially exposing or modifying sensitive inventory or order data and disrupting business operations.
Affected Systems
All installations of the WordPress Barcode Scanner with Inventory & Order Manager plugin with a version of 1.13.1 or earlier are affected. The vulnerability is inherent to these older releases and does not apply to later versions such as 1.13.6 and above.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve accessing plugin pages over HTTP/HTTPS without authentication, where an attacker can invoke privileged API endpoints. Since no authentication is required, the risk of exploitation is high in any site where the plugin is active and accessible.
OpenCVE Enrichment