Description
Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.
Published: 2026-08-31
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Apply Patch
AI Analysis

Impact

The vulnerability in WordPress Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 exposes subscriber-sensitive information. The flaw allows an attacker to retrieve confidential data that was otherwise protected by the plugin’s access controls, compromising confidentiality. The weakness is classified as CWE-201, which denotes exposure of sensitive information.

Affected Systems

Ukrainian vendor "UKR Solution" publishes the Print Barcode Labels for your WooCommerce products/orders plugin. Victim systems include any WordPress site running this plugin up to and including version 4.0.0. No additional affected products or versions are listed in the CNA data.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, but the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, as an attacker can submit requests through the plugin’s interface or potentially via the administrative area of WordPress. Exact exploitation conditions are not detailed in the description, so the assumption is that the attacker would need some level of access to invoke the vulnerable functionality, but the data exposed can be accessed by anyone who can trigger the affected endpoint.

Generated by OpenCVE AI on August 31, 2026 at 21:26 UTC.

Remediation

Vendor Solution

Update the WordPress Print Barcode Labels for your WooCommerce products/orders Plugin to the latest available version (at least 4.0.1).


OpenCVE Recommended Actions

  • Update the WordPress Print Barcode Labels for your WooCommerce products/orders Plugin to version 4.0.1 or later.
  • If the update cannot be applied immediately, temporarily deactivate the plugin to prevent further data exposure.
  • Review and tighten user permissions for WordPress admin areas, ensuring only trusted accounts can access plugin configuration and data retrieval functions.

Generated by OpenCVE AI on August 31, 2026 at 21:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Ukr Solution
Ukr Solution print Barcode Labels For Your Woocommerce Products/orders
Wordpress
Wordpress wordpress
Vendors & Products Ukr Solution
Ukr Solution print Barcode Labels For Your Woocommerce Products/orders
Wordpress
Wordpress wordpress

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.
Title WordPress Print Barcode Labels for your WooCommerce products/orders plugin <= 4.0.0 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ukr Solution Print Barcode Labels For Your Woocommerce Products/orders
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-01T15:15:40.199Z

Reserved: 2026-08-26T17:33:04.627Z

Link: CVE-2026-81280

cve-icon Vulnrichment

Updated: 2026-09-01T15:15:32.273Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T21:17:49.677

Modified: 2026-09-01T20:48:22.513

Link: CVE-2026-81280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:16:28Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data