CVE-2026-62117: WordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.13.1 - SQL Injection vulnerability
Published Oct 10, 2026
·Updated
Subscriber SQL Injection in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.
Affected Software
1 affected component
WordPress Barcode Scanner with Inventory & Order Manager<=1.13.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Barcode Scanner with Inventory & Order Managerto a version that resolves this vulnerability.Fixed in 1.13.6
Event History
Oct 10, 2026
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Subscriber-level access to a WordPress site running the affected plugin. No user interaction is required.
2
What is the potential impact?
The vulnerability is an SQL injection issue with high confidentiality impact and low availability impact. The provided vector indicates the scope may extend beyond the vulnerable component.