Extension WordPress

Vulnérabilités Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Cette page rassemble les failles publiées pour Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale), leurs plages de versions affectées et les correctifs signalés dans la base locale.

16Vulnérabilités
4Critiques
16Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

16 fiches

CVE-2026-4880 Critique · 9,8
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Barcode Scanner (+Mobile App) <= 1.11.0 – Unauthenticated Privilege Escalation via Insecure Token Authentication

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via insecure token-based authentication in all versions up to, and including, 1.11.0. This is due…

Versions affectées

*-1.11.0

Correctif

1.12.0

Publication

15/04/2026

CVE-2026-42645 Moyenne · 4,3
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Barcode Scanner with Inventory & Order Manager <= 1.11.0 – Cross-Site Request Forgery

The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.11.0. This is due to missing or incorrect nonce validation on a function. This makes…

Versions affectées

*-1.11.0

Correctif

1.12.0

Publication

18/03/2026

CVE-2025-58972 Faible · 2,7
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Barcode Scanner with Inventory & Order Manager <= 1.10.4 – Authenticated (Shop Manager+) Directory Traversal

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.10.4. This makes it possible for authenticated attackers,…

Versions affectées

*-1.10.4

Correctif

1.10.5

Publication

15/10/2025

CVE-2025-54715 Moyenne · 4,9
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Barcode Scanner with Inventory & Order Manager <= 1.9.0 – Authenticated (Admin+) Arbitrary File Download

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.0. This makes it possible for authenticated attackers,…

Versions affectées

*-1.9.0

Correctif

1.9.1

Publication

14/08/2025

CVE-2025-22723 Élevée · 7,2
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Barcode Scanner with Inventory & Order Manager <= 1.6.7 – Authenticated (Admin+) Arbitrary File Upload

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.6.7.…

Versions affectées

*-1.6.7

Correctif

1.7.0

Publication

15/01/2025

CVE-2024-54265 Moyenne · 6,1
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Barcode Scanner with Inventory & Order Manager <= 1.6.6 – Reflected Cross-Site Scripting

The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-1.6.6

Correctif

1.6.7

Publication

10/12/2024

CVE-2024-38708 Élevée · 8,5
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Barcode Scanner with Inventory & Order Manager <= 1.6.1 – Authenticated (Subscriber+) SQL Injection

The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…

Versions affectées

*-1.6.1

Correctif

1.6.2

Publication

11/07/2024

CVE-2024-34556 Moyenne · 5,3
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Barcode Scanner with Inventory & Order Manager <= 1.5.4 – Unauthenticated Information Exposure

The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.4 via exported…

Versions affectées

*-1.5.4

Correctif

1.5.5

Publication

07/05/2024

CVE-2024-34557 Moyenne · 4,3
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Barcode Scanner with Inventory & Order Manager <= 1.5.4 – Cross-Site Request Forgery

The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.4. This is due to missing or incorrect nonce validation on the pageSettingsUpdate() function. This…

Versions affectées

*-1.5.4

Correctif

1.5.5

Publication

07/05/2024

CVE-2024-2661 Élevée · 8,8
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Barcode Scanner with Inventory & Order Manager <= 1.5.4 – Authenticated (Subscriber+) SQL Injection

The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to blind SQL Injection via the ‘currentIds’ parameter in all versions up to, and…

Versions affectées

*-1.5.4

Correctif

1.5.5

Publication

30/04/2024

CVE-2024-33567 Critique · 9,8
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Barcode Scanner with Inventory & Order Manager <= 1.5.3 – Unauthenticated Privilege Escalation

The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.3. This is due…

Versions affectées

*-1.5.3

Correctif

1.5.4

Publication

25/04/2024

CVE-2024-33565 Moyenne · 5,3
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Barcode Scanner with Inventory & Order Manager <= 1.5.3 – Missing Authorization

The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.5.3. This makes it possible for unauthenticated…

Versions affectées

*-1.5.3

Correctif

1.5.4

Publication

25/04/2024

CVE-2024-32589 Moyenne · 6,4
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Barcode Scanner with Inventory & Order Manager <= 1.5.3 – Missing Authorization

The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.5.3. This makes it possible for authenticated…

Versions affectées

*-1.5.3

Correctif

1.5.4

Publication

16/04/2024

CVE-2024-27998 Moyenne · 6,1
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Barcode Scanner with Inventory & Order Manager <= 1.5.3 – Reflected Cross-Site Scripting

The Barcode Scanner with Inventory & Order Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-1.5.3

Correctif

1.5.4

Publication

15/03/2024

CVE-2023-52215 Critique · 9,8
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Barcode Scanner with Inventory & Order Manager <= 1.5.1 – Unauthenticated SQL Injection via userToken

The Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘userToken’ parameter in all versions up to 1.5.2 (exclusive) due to insufficient escaping…

Versions affectées

[*, 1.5.2)

Correctif

1.5.2

Publication

08/01/2024

CVE-2023-52221 Critique · 9,8
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

Barcode Scanner with Inventory & Order Manager <= 1.5.1 – Unauthenticated Arbitrary File Upload via uploadFile

The Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'uploadFile' function in all versions up…

Versions affectées

*-1.5.1

Correctif

1.5.2

Publication

08/01/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités