Executive brief
A WordPress plugin used to generate and print barcode labels for WooCommerce orders and products exposes sensitive subscriber information to unauthorized access. An attacker with basic subscriber-level permissions can retrieve private data such as customer details, potentially leading to privacy violations and customer trust damage.
Technical details
The vulnerability is a sensitive data exposure flaw in the Print Barcode Labels for WooCommerce plugin versions 4.0.0 and earlier. The vulnerability allows attackers with subscriber-level privileges to access restricted information that should not be visible at that permission level. The flaw stems from improper access control checks in the plugin's functionality. No special attack vector or user interaction is required beyond having a valid subscriber account. Exploitation could expose customer names, emails, order details, and other sensitive information. The vulnerability has been patched in version 4.0.1.
Affected products
- UkrSolution Print Barcode Labels for WooCommerce <=4.0.0
Timeline
- 2026-08-31: disclosed
- 2026-08-31: patched: Version 4.0.1 available