Impact
The vulnerability in WordPress Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 exposes subscriber-sensitive information. The flaw allows an attacker to retrieve confidential data that was otherwise protected by the plugin’s access controls, compromising confidentiality. The weakness is classified as CWE-201, which denotes exposure of sensitive information.
Affected Systems
Ukrainian vendor "UKR Solution" publishes the Print Barcode Labels for your WooCommerce products/orders plugin. Victim systems include any WordPress site running this plugin up to and including version 4.0.0. No additional affected products or versions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, but the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, as an attacker can submit requests through the plugin’s interface or potentially via the administrative area of WordPress. Exact exploitation conditions are not detailed in the description, so the assumption is that the attacker would need some level of access to invoke the vulnerable functionality, but the data exposed can be accessed by anyone who can trigger the affected endpoint.
OpenCVE Enrichment