CVE-2026-4880Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via insecure token-based authentication in all versions up to, and including, 1.11.0. This is due to the plugin trusting a user-supplied Base64-encoded user ID in the token parameter to identify users, leaking valid authentication tokens through the 'barcodeScannerConfigs' action, and lacking meta-key restrictions on the 'setUserMeta' action. This makes it possible for unauthenticated attackers to escalate their privileges to that of an administrator by first spoofing the admin user ID to leak their authentication token, then using that token to update any user's 'wp_capabilities' meta to gain full administrative access.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Exploit: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-04-16); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-04-15: 1Mentions · 2026-04-16: 4Mentions · 2026-04-17: 1Patch / Workaround · 2026-04-16: 2Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 4Technical Details · 2026-04-17: 104-1504-1604-17
Signal classification3 categories
Disclosure
466.7%
Exploit
116.7%
Patch
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-151
Exploit1
2026-04-164
Disclosure3Patch1
2026-04-171
Disclosure1
Full discourse6 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🌐 مدونة WordPress : 🪗 إضافة Accordion Slider (الأخطر): التقييم: 9.8 | (CVE-2026-6443) ⚠️عبارة عن Backdoor مزروع عمداً في الإصدار (1.4.6). 🧩 إضافات أخرى (بتقييم 9.8): ⚠️ تسمح برفع ملفات وتخطي المصادقة في الإضافات التالية: 📂 إضافة WebStack برقم (CVE-2026-1555) 💳 إضافة Visa Plugin برقم (CVE-2026-3461) 🔀 إضافة Barcode Scanner برقم (CVE-2026-4880)

    Post summary

    The blog post announces four high‑severity CVEs (rated 9.8) in WordPress plugins, highlighting backdoor presence and auth bypass, with no patches or PoC provided.

    110021.3K
    48.7K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4880 — CVSS 9.8/10 ██████████ The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/SSjdzqT5b5

    Post summary

    The tweet announces CVE‑2026‑4880, a critical vulnerability (CVSS 9.8/10) affecting the Barcode Scanner mobile app and related inventory/pos systems, and urges users to apply the patch immediately.

    1000055
    23 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4880 The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via inse… https://www.cve.org/CVERecord?id=CVE-2026-4880

    Post summary

    The tweet announces CVE‑2026‑4880, indicating a privilege‑escalation flaw in the Barcode Scanner WordPress plugin, but it provides no PoC, exploit, or patch information.

    00000107
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4880 Privilege Escalation via Insecure Token Authentication in Barcode Scanner WordPress Plugin 1.11.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4880

    Post summary

    The text announces CVE‑2026‑4880, detailing a privilege escalation flaw in Barcode Scanner WordPress Plugin 1.11.0 caused by insecure token authentication.

    0000063
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-4880 The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPre… CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-4880 #WordPress #CyberSecurity #InfoSec

    Post summary

    A critical vulnerability, CVE-2026-4880, has been disclosed for WordPress plugins with a CVSS score of 9.8 and no patch available yet. Full analysis and details are posted online.

    000001
    145 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-4880: Barcode Scanner (+Mobile App) <= ... Base64 user ID spoofing + token leakage = instant WordPress admin takeover - this plugin literally hands attackers the k... https://zerodaysignal.com/vulnerability/CVE-2026-4880 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-4880 enables attackers to spoof Base64 user IDs and leak tokens, allowing instant WordPress admin takeover; no fix or PoC code is cited.

    00000101
    218 followersView on X

Explore more