SQL Injection Vulnerability in Barcode Scanner by Patchstack
CVE-2026-62117

8.5HIGH

What is CVE-2026-62117?

A SQL injection vulnerability exists in the Barcode Scanner with Inventory & Order Manager plugin for WordPress, affecting versions up to 1.13.1. This weakness allows attackers to manipulate SQL queries, potentially leading to unauthorized access to sensitive data. It is crucial for users of this plugin to apply the latest patches and updates to protect their systems from potential exploitation.

Affected Version(s)

Barcode Scanner with Inventory & Order Manager <= 1.13.1

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

she11f | Patchstack Bug Bounty Program
.