CVE-2024-43310 MEDIUM

CVE-2024-43310: WordPress Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin <= 3.4.9 - Broken Access Control vulnerability

Vendor Ukrsolution
Product Print Barcode Labels for your WooCommerce products/orders
Weakness CWE-862 · Missing authorization
Published November 1, 2024
Last update April 28, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Missing Authorization vulnerability in UkrSolution Print Barcode Labels for your WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Barcode Labels for your WooCommerce products/orders: from n/a through 3.4.9.

Explanation of Vulnerability in Simple Terms

02Summary

The Print Barcode Labels for WooCommerce plugin through version 3.4.9 fails to properly check user permissions before allowing access to sensitive barcode and order data. A logged-in user with low privileges can read barcode labels and order information they should not have access to. Update to a version newer than 3.4.9.

What an attacker can do

03Attacker Capabilities

Read barcode labels and order data belonging to other users or orders.

Potential impact on your site

04Site Impact

Customer order and barcode data may be exposed to other logged-in users with lower privilege levels.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege account on the WooCommerce site (e.g., customer or subscriber role).

Key dates

06Disclosure timeline

November 1, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE