CVE-2024-33567
WordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.5.3 - Unauthenticated Privilege Escalation vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Privilege Management vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Privilege Escalation.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.
Una vulnerabilidad de gestión de privilegios incorrecta en UkrSolution Barcode Scanner with Inventory & Order Manager permite una escalada de privilegios. Este problema afecta a Barcode Scanner with Inventory & Order Manager: desde n/a hasta 1.5.3.
The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.3. This is due to the plugin not properly restricting user meta values that can be updated. This makes it possible for unauthenticated attackers to elevate their privileges to an administrator.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-04-24 CVE Reserved
- 2024-04-25 CVE Published
- 2024-05-18 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
CAPEC
- CAPEC-233: Privilege Escalation
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Barcode Scanner Lite Pos To Manage Products Inventory And Orders Search vendor "Barcode Scanner Lite Pos To Manage Products Inventory And Orders" | Barcode Scanner Lite Pos To Manage Products Inventory And Orders Search vendor "Barcode Scanner Lite Pos To Manage Products Inventory And Orders" for product "Barcode Scanner Lite Pos To Manage Products Inventory And Orders" | >= 0.0.0 <= 1.5.3 Search vendor "Barcode Scanner Lite Pos To Manage Products Inventory And Orders" for product "Barcode Scanner Lite Pos To Manage Products Inventory And Orders" and version " >= 0.0.0 <= 1.5.3" | en |
Affected
|