Sceawere

Vulnerability Detail

CVE-2026-81280UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Print Barcode Labels Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
11h ago
Vendor
UKR Solution
Product
Print Barcode Labels for your WooCommerce products/orders
Attack Type
CWE-201 Insertion of Sensitive Information Into Sent Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-31T21:17:49.677Z",
  "pubdate": "2026-08-31T21:17:49.677Z",
  "executiveSummary": "This vulnerability is classified as Sensitive Data Exposure affecting the 'Print Barcode Labels for your WooCommerce products/orders' plugin for WordPress.\nThe flaw allows unauthorized users to access sensitive customer and order information that should be restricted to authenticated administrators.\nThe vulnerability resides in the plugin's data handling mechanisms, which fail to properly implement access control checks for specific request parameters or endpoints used for generating barcode labels.\nSuccessful exploitation enables an unauthenticated or low-privileged attacker to retrieve personally identifiable information (PII) or sensitive order details by manipulating requests targeted at the plugin's functionality.\nThe risk is categorized as significant due to the potential for data breaches involving customer addresses, order specifics, and product data, directly impacting user privacy and compliance with data protection regulations.\nExploitation requires no special privileges beyond network access to the target WordPress installation, and the attacker does not need to bypass complex authentication layers if the vulnerable endpoint is exposed.",
  "technicalDetails": "The vulnerability is rooted in an Insecure Direct Object Reference (IDOR) or insufficient authorization logic within the 'Print Barcode Labels for your WooCommerce products/orders' plugin, specifically affecting versions 4.0.0 and earlier.\nThe plugin exposes functionality designed to generate and print barcodes for WooCommerce orders or products. During this process, the backend handlers responsible for retrieving order or product details fail to perform comprehensive capability checks (such as 'manage_woocommerce' or 'edit_shop_orders') before rendering the output.\nThe attack flow initiates when an attacker crafts a direct HTTP request to the vulnerable plugin endpoint. By manipulating request parameters (e.g., passing specific order IDs or product IDs), the attacker can bypass existing access controls.\nBecause the server-side code does not verify whether the current user session possesses the appropriate administrative privileges, the system proceeds to execute the query and retrieve sensitive data associated with the provided parameters.\nThe payload behavior involves the systematic enumeration of IDs to scrape data from the WooCommerce database. Since the plugin's response includes detailed order or product information—which is intended only for authorized personnel—the attacker receives this private data in the HTTP response body.\nThe affected components are the AJAX handlers or direct script entry points used for barcode generation. These components lack proper nonce verification and user capability validation, allowing for unauthorized data access.\nPost-exploitation, an attacker can exfiltrate customer names, physical addresses, contact information, and purchase history. This information is highly valuable for secondary attacks such as social engineering, phishing campaigns, or identity theft. Furthermore, because the vulnerability allows for enumeration via incrementing numeric IDs, it is trivial to automate the bulk extraction of a database's entire order history.\nThe vulnerability is accessible over the network without the requirement for prior authentication or elevated privileges. It functions by abusing the existing administrative logic, which remains active and unprotected against unauthenticated interactions in the specified plugin versions."
}
CVE-2026-81280: Print Barcode Labels Information Disclosure (MEDIUM Severity, CVSS: 6.5) - Sceawere