CVE-2026-81280 MEDIUM

CVE-2026-81280: WordPress Print Barcode Labels for your WooCommerce products/orders plugin <= 4.0.0 - Sensitive Data Exposure vulnerability

Vendor Ukr Solution
Product Print Barcode Labels for your WooCommerce products/orders
Weakness CWE-201
Published August 31, 2026
Last update September 1, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.

Explanation of Vulnerability in Simple Terms

02Summary

The Print Barcode Labels plugin for WooCommerce through version 4.0.0 exposes sensitive information in outgoing data. An authenticated user with low privileges can trigger the plugin to leak confidential details in network communications. The vulnerability does not allow modification or deletion of data, but the information disclosure poses a risk to order and customer privacy.

What an attacker can do

03Attacker Capabilities

Read sensitive information sent by the plugin in network traffic or responses.

Potential impact on your site

04Site Impact

Customer and order data may be exposed to authenticated users who should not have access to it.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege WooCommerce user account (e.g., customer or shop manager).

Key dates

06Disclosure timeline

August 31, 2026 CVE published
September 1, 2026 Record updated

Related vulnerabilities

08Related CVE