LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-4880 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: April 16, 2026

Barcode Scanner (+Mobile App) - Privilege Escalation

Published: April 16, 2026Updated: April 16, 2026Remote Exploitable

Overview

Barcode Scanner (+Mobile App) WordPress plugin <= 1.11.0 contains a privilege escalation caused by insecure token-based authentication trusting user-supplied Base64 user ID and lacking meta-key restrictions, letting unauthenticated attackers escalate to admin by spoofing tokens.

Severity & Score

Severity: Critical
CVSS Score: 9.8

Impact

Unauthenticated attackers can escalate privileges to administrator, gaining full control over the WordPress site.

Mitigation

Update to the latest version beyond 1.11.0 where this issue is fixed.

Details

CVE ID
CVE-2026-4880
Severity
Critical
CVSS Score
9.8
Type
broken_access_control
Status
new

CWE

  • CWE-269

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H