Print Barcode Labels for your WooCommerce products/orders <= 3.4.10 - Missing Authorization
medium
The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.4.10. This makes it possible for authenticated attackers, with Subscriber-leve...
- CVSS:
- 4.3
- Affected:
- up to 3.4.10
- Fixed in:
- 3.4.11
- Disclosed:
- Jan 24, 2025
CVE-2025-24603 on NVD →
Print Barcode Labels for your WooCommerce products/orders <= 3.4.9 - Missing Authorization
medium
The Print Barcode Labels for your WooCommerce products/orders plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the search() function in versions up to, and including, 3.4.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to searc...
- CVSS:
- 4.3
- Affected:
- up to 3.4.9
- Fixed in:
- 3.4.10
- Disclosed:
- Aug 16, 2024
CVE-2024-43310 on NVD →
Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce <= 3.4.6 - Authenticated(Subscriber+) Stored Cross-Site Scripting via Templates
medium
The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template and javascript label fields in all versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. This make...
- CVSS:
- 6.4
- Affected:
- up to 3.4.6
- Fixed in:
- 3.4.7
- Disclosed:
- Apr 29, 2024
CVE-2024-1679 on NVD →
Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce <= 3.4.6 - Improper Authorization
medium
The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to an improper capability check on 42 separate AJAX functions in all versions up to, and including, 3.4.6. This ma...
- CVSS:
- 6.3
- Affected:
- up to 3.4.6
- Fixed in:
- 3.4.7
- Disclosed:
- Apr 29, 2024
CVE-2024-1677 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database