Cross Site Scripting Vulnerability in Barcode Scanner with Inventory & Order Manager by WordPress
CVE-2026-62116

7.1HIGH

What is CVE-2026-62116?

The Barcode Scanner with Inventory & Order Manager plugin for WordPress has been identified to have a vulnerability that allows unauthenticated users to inject malicious scripts via XSS. This can lead to potential data theft and manipulation, posing significant risks to web application integrity. It is crucial for users of versions 1.13.1 and below to apply patches and update promptly to safeguard their systems.

Affected Version(s)

Barcode Scanner with Inventory & Order Manager <= 1.13.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hhhai | Patchstack Bug Bounty Program
.