Barcode Scanner (+Mobile App) <= 1.11.0 - Unauthenticated Privilege Escalation via Insecure Token Authentication
critical
The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via insecure token-based authentication in all versions up to, and including, 1.11.0. This is due to the plugin trusting a user-supplied Base64-encoded user ID...
- CVSS:
- 9.8
- Affected:
- up to 1.11.0
- Fixed in:
- 1.12.0
- Disclosed:
- Apr 15, 2026
CVE-2026-4880 on NVD →
Barcode Scanner with Inventory & Order Manager <= 1.11.0 - Cross-Site Request Forgery
medium
The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.11.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a f...
- CVSS:
- 4.3
- Affected:
- up to 1.11.0
- Fixed in:
- 1.12.0
- Disclosed:
- Mar 18, 2026
CVE-2026-42645 on NVD →
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] <= 1.10.4 (unfixed)
unknown
[en] Path Traversal: '.../...//' vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Path Traversal.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.10.4.
- Affected:
- up to 1.10.4
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2025
CVE-2025-58972 on NVD →
Barcode Scanner with Inventory & Order Manager <= 1.10.4 - Authenticated (Shop Manager+) Directory Traversal
low
The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.10.4. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to perform actions on...
- CVSS:
- 2.7
- Affected:
- up to 1.10.4
- Fixed in:
- 1.10.5
- Disclosed:
- Oct 15, 2025
CVE-2025-58972 on NVD →
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.4
unknown
[en] Missing Authorization vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.4
- Disclosed:
- Aug 31, 2025
CVE-2024-32589 on NVD →
Barcode Scanner with Inventory & Order Manager <= 1.9.0 - Authenticated (Admin+) Arbitrary File Download
medium
The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of ar...
- CVSS:
- 4.9
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.1
- Disclosed:
- Aug 14, 2025
CVE-2025-54715 on NVD →
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.9.1
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager allows Path Traversal. This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.9.0.
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.1
- Disclosed:
- Aug 14, 2025
CVE-2025-54715 on NVD →
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.7.0
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Upload a Web Shell to a Web Server. This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.6.7.
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
- Disclosed:
- Jan 21, 2025
CVE-2025-22723 on NVD →
Barcode Scanner with Inventory & Order Manager <= 1.6.7 - Authenticated (Admin+) Arbitrary File Upload
high
The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.6.7. This makes it possible for authenticated attackers, with Administrator-level...
- CVSS:
- 7.2
- Affected:
- up to 1.6.7
- Fixed in:
- 1.7.0
- Disclosed:
- Jan 15, 2025
CVE-2025-22723 on NVD →
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.6.7
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Reflected XSS.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.6.6.
- Affected:
- up to 1.6.7
- Fixed in:
- 1.6.7
- Disclosed:
- Dec 13, 2024
CVE-2024-54265 on NVD →
Barcode Scanner with Inventory & Order Manager <= 1.6.6 - Reflected Cross-Site Scripting
medium
The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...
- CVSS:
- 6.1
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.7
- Disclosed:
- Dec 10, 2024
CVE-2024-54265 on NVD →
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.6.2
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows SQL Injection.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.6.1.
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.2
- Disclosed:
- Jul 22, 2024
CVE-2024-38708 on NVD →
Barcode Scanner with Inventory & Order Manager <= 1.6.1 - Authenticated (Subscriber+) SQL Injection
high
The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, wi...
- CVSS:
- 8.5
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.2
- Disclosed:
- Jul 11, 2024
CVE-2024-38708 on NVD →
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.4
unknown
[en] Missing Authorization vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.4
- Disclosed:
- Jun 9, 2024
CVE-2024-33565 on NVD →
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.4
unknown
[en] Improper Privilege Management vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Privilege Escalation.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.4
- Disclosed:
- May 17, 2024
CVE-2024-33567 on NVD →
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.5
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.4.
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- May 9, 2024
CVE-2024-34556 on NVD →
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.4.
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- May 9, 2024
CVE-2024-34557 on NVD →
Barcode Scanner with Inventory & Order Manager <= 1.5.4 - Unauthenticated Information Exposure
medium
The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.4 via exported files. This makes it possible for unauthenticated attackers to extract sensiti...
- CVSS:
- 5.3
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.5
- Disclosed:
- May 7, 2024
CVE-2024-34556 on NVD →
Barcode Scanner with Inventory & Order Manager <= 1.5.4 - Cross-Site Request Forgery
medium
The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.4. This is due to missing or incorrect nonce validation on the pageSettingsUpdate() function. This makes it possible for unauthenticated attackers to update plugin se...
- CVSS:
- 4.3
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.5
- Disclosed:
- May 7, 2024
CVE-2024-34557 on NVD →
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.5
unknown
[en] The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to blind SQL Injection via the ‘currentIds’ parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and la...
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- May 2, 2024
CVE-2024-2661 on NVD →
Barcode Scanner with Inventory & Order Manager <= 1.5.4 - Authenticated (Subscriber+) SQL Injection
high
The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to blind SQL Injection via the ‘currentIds’ parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of...
- CVSS:
- 8.8
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.5
- Disclosed:
- Apr 30, 2024
CVE-2024-2661 on NVD →
Barcode Scanner with Inventory & Order Manager <= 1.5.3 - Unauthenticated Privilege Escalation
critical
The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.3. This is due to the plugin not properly restricting user meta values that can be updated. This makes...
- CVSS:
- 9.8
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.4
- Disclosed:
- Apr 25, 2024
CVE-2024-33567 on NVD →
Barcode Scanner with Inventory & Order Manager <= 1.5.3 - Missing Authorization
medium
The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.5.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.4
- Disclosed:
- Apr 25, 2024
CVE-2024-33565 on NVD →
Barcode Scanner with Inventory & Order Manager <= 1.5.3 - Missing Authorization
medium
The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject malicious web script...
- CVSS:
- 6.4
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.4
- Disclosed:
- Apr 16, 2024
CVE-2024-32589 on NVD →
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.4
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Reflected XSS.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.4
- Disclosed:
- Mar 19, 2024
CVE-2024-27998 on NVD →
Barcode Scanner with Inventory & Order Manager <= 1.5.3 - Reflected Cross-Site Scripting
medium
The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...
- CVSS:
- 6.1
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.4
- Disclosed:
- Mar 15, 2024
CVE-2024-27998 on NVD →
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.2
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in UkrSolution Barcode Scanner and Inventory manager.This issue affects Barcode Scanner and Inventory manager: from n/a through 1.5.1.
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Jan 24, 2024
CVE-2023-52221 on NVD →
Barcode Scanner with Inventory & Order Manager <= 1.5.1 - Unauthenticated SQL Injection via userToken
critical
The Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘userToken’ parameter in all versions up to 1.5.2 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t...
- CVSS:
- 9.8
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Jan 8, 2024
CVE-2023-52215 on NVD →
Barcode Scanner with Inventory & Order Manager <= 1.5.1 - Unauthenticated Arbitrary File Upload via uploadFile
critical
The Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'uploadFile' function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attacke...
- CVSS:
- 9.8
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Jan 8, 2024
CVE-2023-52221 on NVD →
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) [barcode-scanner-lite-pos-to-manage-products-inventory-and-orders] < 1.5.2
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce.This issue affects Simple Inventory Management – just scan barcode to manage products and orders. For WooC...
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Jan 8, 2024
CVE-2023-52215 on NVD →