plugin

Barcode Scanner Lite Pos To Manage Products Inventory And Orders Vulnerabilities

30 known security issues reported for the Barcode Scanner Lite Pos To Manage Products Inventory And Orders WordPress plugin. Most recent disclosed Apr 15, 2026.

4 critical 3 high 8 medium 1 low

Running Barcode Scanner Lite Pos To Manage Products Inventory And Orders on your site? Check whether your installed version is affected.

Scan your site free

Barcode Scanner (+Mobile App) <= 1.11.0 - Unauthenticated Privilege Escalation via Insecure Token Authentication

critical

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via insecure token-based authentication in all versions up to, and including, 1.11.0. This is due to the plugin trusting a user-supplied Base64-encoded user ID...

CVSS:
9.8
Affected:
up to 1.11.0
Fixed in:
1.12.0
Disclosed:
Apr 15, 2026

CVE-2026-4880 on NVD →

Barcode Scanner with Inventory & Order Manager <= 1.11.0 - Cross-Site Request Forgery

medium

The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.11.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a f...

CVSS:
4.3
Affected:
up to 1.11.0
Fixed in:
1.12.0
Disclosed:
Mar 18, 2026

CVE-2026-42645 on NVD →

Barcode Scanner (+Mobile App) &#8211; Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] <= 1.10.4 (unfixed)

unknown

[en] Path Traversal: '.../...//' vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Path Traversal.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.10.4.

Affected:
up to 1.10.4
Fix:
No patched version reported
Disclosed:
Nov 6, 2025

CVE-2025-58972 on NVD →

Barcode Scanner with Inventory & Order Manager <= 1.10.4 - Authenticated (Shop Manager+) Directory Traversal

low

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.10.4. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to perform actions on...

CVSS:
2.7
Affected:
up to 1.10.4
Fixed in:
1.10.5
Disclosed:
Oct 15, 2025

CVE-2025-58972 on NVD →

Barcode Scanner (+Mobile App) &#8211; Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.4

unknown

[en] Missing Authorization vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.

Affected:
up to 1.5.4
Fixed in:
1.5.4
Disclosed:
Aug 31, 2025

CVE-2024-32589 on NVD →

Barcode Scanner with Inventory & Order Manager <= 1.9.0 - Authenticated (Admin+) Arbitrary File Download

medium

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of ar...

CVSS:
4.9
Affected:
up to 1.9.0
Fixed in:
1.9.1
Disclosed:
Aug 14, 2025

CVE-2025-54715 on NVD →

Barcode Scanner (+Mobile App) &#8211; Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.9.1

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager allows Path Traversal. This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.9.0.

Affected:
up to 1.9.1
Fixed in:
1.9.1
Disclosed:
Aug 14, 2025

CVE-2025-54715 on NVD →

Barcode Scanner (+Mobile App) &#8211; Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.7.0

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Upload a Web Shell to a Web Server. This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.6.7.

Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Jan 21, 2025

CVE-2025-22723 on NVD →

Barcode Scanner with Inventory & Order Manager <= 1.6.7 - Authenticated (Admin+) Arbitrary File Upload

high

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.6.7. This makes it possible for authenticated attackers, with Administrator-level...

CVSS:
7.2
Affected:
up to 1.6.7
Fixed in:
1.7.0
Disclosed:
Jan 15, 2025

CVE-2025-22723 on NVD →

Barcode Scanner (+Mobile App) &#8211; Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.6.7

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Reflected XSS.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.6.6.

Affected:
up to 1.6.7
Fixed in:
1.6.7
Disclosed:
Dec 13, 2024

CVE-2024-54265 on NVD →

Barcode Scanner with Inventory & Order Manager <= 1.6.6 - Reflected Cross-Site Scripting

medium

The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...

CVSS:
6.1
Affected:
up to 1.6.6
Fixed in:
1.6.7
Disclosed:
Dec 10, 2024

CVE-2024-54265 on NVD →

Barcode Scanner (+Mobile App) &#8211; Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.6.2

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows SQL Injection.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.6.1.

Affected:
up to 1.6.2
Fixed in:
1.6.2
Disclosed:
Jul 22, 2024

CVE-2024-38708 on NVD →

Barcode Scanner with Inventory & Order Manager <= 1.6.1 - Authenticated (Subscriber+) SQL Injection

high

The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, wi...

CVSS:
8.5
Affected:
up to 1.6.1
Fixed in:
1.6.2
Disclosed:
Jul 11, 2024

CVE-2024-38708 on NVD →

Barcode Scanner (+Mobile App) &#8211; Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.4

unknown

[en] Missing Authorization vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.

Affected:
up to 1.5.4
Fixed in:
1.5.4
Disclosed:
Jun 9, 2024

CVE-2024-33565 on NVD →

Barcode Scanner (+Mobile App) &#8211; Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.4

unknown

[en] Improper Privilege Management vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Privilege Escalation.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.

Affected:
up to 1.5.4
Fixed in:
1.5.4
Disclosed:
May 17, 2024

CVE-2024-33567 on NVD →

Barcode Scanner (+Mobile App) &#8211; Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.5

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.4.

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
May 9, 2024

CVE-2024-34556 on NVD →

Barcode Scanner (+Mobile App) &#8211; Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.5

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.4.

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
May 9, 2024

CVE-2024-34557 on NVD →

Barcode Scanner with Inventory & Order Manager <= 1.5.4 - Unauthenticated Information Exposure

medium

The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.4 via exported files. This makes it possible for unauthenticated attackers to extract sensiti...

CVSS:
5.3
Affected:
up to 1.5.4
Fixed in:
1.5.5
Disclosed:
May 7, 2024

CVE-2024-34556 on NVD →

Barcode Scanner with Inventory & Order Manager <= 1.5.4 - Cross-Site Request Forgery

medium

The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.4. This is due to missing or incorrect nonce validation on the pageSettingsUpdate() function. This makes it possible for unauthenticated attackers to update plugin se...

CVSS:
4.3
Affected:
up to 1.5.4
Fixed in:
1.5.5
Disclosed:
May 7, 2024

CVE-2024-34557 on NVD →

Barcode Scanner (+Mobile App) &#8211; Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.5

unknown

[en] The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to blind SQL Injection via the ‘currentIds’ parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and la...

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
May 2, 2024

CVE-2024-2661 on NVD →

Barcode Scanner with Inventory & Order Manager <= 1.5.4 - Authenticated (Subscriber+) SQL Injection

high

The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to blind SQL Injection via the ‘currentIds’ parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of...

CVSS:
8.8
Affected:
up to 1.5.4
Fixed in:
1.5.5
Disclosed:
Apr 30, 2024

CVE-2024-2661 on NVD →

Barcode Scanner with Inventory & Order Manager <= 1.5.3 - Unauthenticated Privilege Escalation

critical

The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.3. This is due to the plugin not properly restricting user meta values that can be updated. This makes...

CVSS:
9.8
Affected:
up to 1.5.3
Fixed in:
1.5.4
Disclosed:
Apr 25, 2024

CVE-2024-33567 on NVD →

Barcode Scanner with Inventory & Order Manager <= 1.5.3 - Missing Authorization

medium

The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.5.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.5.3
Fixed in:
1.5.4
Disclosed:
Apr 25, 2024

CVE-2024-33565 on NVD →

Barcode Scanner with Inventory & Order Manager <= 1.5.3 - Missing Authorization

medium

The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject malicious web script...

CVSS:
6.4
Affected:
up to 1.5.3
Fixed in:
1.5.4
Disclosed:
Apr 16, 2024

CVE-2024-32589 on NVD →

Barcode Scanner (+Mobile App) &#8211; Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.4

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Reflected XSS.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.

Affected:
up to 1.5.4
Fixed in:
1.5.4
Disclosed:
Mar 19, 2024

CVE-2024-27998 on NVD →

Barcode Scanner with Inventory & Order Manager <= 1.5.3 - Reflected Cross-Site Scripting

medium

The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...

CVSS:
6.1
Affected:
up to 1.5.3
Fixed in:
1.5.4
Disclosed:
Mar 15, 2024

CVE-2024-27998 on NVD →

Barcode Scanner (+Mobile App) &#8211; Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.2

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in UkrSolution Barcode Scanner and Inventory manager.This issue affects Barcode Scanner and Inventory manager: from n/a through 1.5.1.

Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
Jan 24, 2024

CVE-2023-52221 on NVD →

Barcode Scanner with Inventory & Order Manager <= 1.5.1 - Unauthenticated SQL Injection via userToken

critical

The Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘userToken’ parameter in all versions up to 1.5.2 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t...

CVSS:
9.8
Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
Jan 8, 2024

CVE-2023-52215 on NVD →

Barcode Scanner with Inventory & Order Manager <= 1.5.1 - Unauthenticated Arbitrary File Upload via uploadFile

critical

The Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'uploadFile' function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attacke...

CVSS:
9.8
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Jan 8, 2024

CVE-2023-52221 on NVD →

Barcode Scanner (+Mobile App) &#8211; Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.2

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce.This issue affects Simple Inventory Management – just scan barcode to manage products and orders. For WooC...

Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
Jan 8, 2024

CVE-2023-52215 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database