CVE-2026-62118: WordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.13.1 - Broken Access Control vulnerability
Published Oct 10, 2026
·Updated
Unauthenticated Broken Access Control in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.
Affected Software
1 affected component
WordPress Barcode Scanner with Inventory & Order Manager<=1.13.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Barcode Scanner with Inventory & Order Manager pluginto a version that resolves this vulnerability.Fixed in 1.13.6
Event History
Oct 10, 2026
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker does not need to authenticate, so any remote party able to reach the affected WordPress site may be able to exploit it.
2
Which plugin versions are affected?
The issue affects Barcode Scanner with Inventory & Order Manager versions 1.13.1 and earlier.
3
What is the potential impact?
The provided severity vector indicates low confidentiality, integrity, and availability impact. The issue is rated high with a CVSS score of 7.3.