Vitepos – Point of Sale (POS) for WooCommerce <= 3.4.2 - Authenticated (Cashier+) SQL Injection
medium
The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.5
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.3
- Disclosed:
- Jul 7, 2026
CVE-2026-57385 on NVD →
Vitepos – Point of Sale (POS) for WooCommerce <= 3.4.2 - Unauthenticated Information Exposure
medium
The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.3
- Disclosed:
- Jun 18, 2026
CVE-2026-54841 on NVD →
Vitepos – Point of Sale (POS) for WooCommerce < 3.4.2 - Authenticated (Outlet Manager+) Privilege Escalation
high
The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 3.4.2 (exclusive). This makes it possible for authenticated attackers, with Outlet Manager-level access and above, to elevate their privileges to that of an administrator.
- CVSS:
- 7.2
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.2
- Disclosed:
- Jun 1, 2026
CVE-2026-8157 on NVD →
Vitepos – Point of Sale (POS) for WooCommerce [vitepos-lite] < 3.3.1
unknown
[en] The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the insert_media_attachment() function in all versions up to, and including, 3.3.0. This is due to the save_update_category_img() function accepting user-supplied fi...
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.1
- Disclosed:
- Nov 21, 2025
CVE-2025-13156 on NVD →
Vitepos – Point of Sale (POS) for WooCommerce <= 3.3.0 - Authenticated (Subscriber+) Arbitrary File Upload to Remote Code Execution
high
The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the insert_media_attachment() function in all versions up to, and including, 3.3.0. This is due to the save_update_category_img() function accepting user-supplied file ty...
- CVSS:
- 8.8
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.1
- Disclosed:
- Nov 20, 2025
CVE-2025-13156 on NVD →
Vitepos <= 3.1.7 - Missing Authorization
medium
The Vitepos – Point of sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.7. This makes it possible for authenticated attackers, with Outlet Manager-level access and above, to perform an un...
- CVSS:
- 4.3
- Affected:
- up to 3.1.7
- Fixed in:
- 3.1.8
- Disclosed:
- Apr 17, 2025
CVE-2025-39535 on NVD →
Vitepos – Point of Sale (POS) for WooCommerce [vitepos-lite] < 3.1.8
unknown
[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos allows Authentication Abuse. This issue affects Vitepos: from n/a through 3.1.7.
- Affected:
- up to 3.1.8
- Fixed in:
- 3.1.8
- Disclosed:
- Apr 17, 2025
CVE-2025-39535 on NVD →
Vitepos – Point of Sale (POS) for WooCommerce [vitepos-lite] < 3.1.5
unknown
[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos allows Authentication Abuse. This issue affects Vitepos: from n/a through 3.1.4.
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.5
- Disclosed:
- Apr 1, 2025
CVE-2025-22277 on NVD →
Vitepos <= 3.1.4 - Missing Authorization
medium
The Vitepos – Point of sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauth...
- CVSS:
- 5.3
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.5
- Disclosed:
- Mar 31, 2025
CVE-2025-22277 on NVD →
Vitepos – Point of Sale (POS) for WooCommerce [vitepos-lite] < 3.1.4
unknown
[en] Missing Authorization vulnerability in appsbd Vitepos allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Vitepos: from n/a through 3.1.3.
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Feb 22, 2025
CVE-2025-26750 on NVD →
Vitepos – Point of sale (POS) <= 3.1.3 - Missing Authorization
medium
The Vitepos – Point of sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauth...
- CVSS:
- 4.3
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Feb 14, 2025
CVE-2025-26750 on NVD →
Vitepos – Point of Sale (POS) for WooCommerce [vitepos-lite] < 3.0.2
unknown
[en] Missing Authorization vulnerability in appsbd Vitepos.This issue affects Vitepos: from n/a through 3.0.1.
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.2
- Disclosed:
- May 8, 2024
CVE-2024-33574 on NVD →
Vitepos <= 3.0.1 - Missing Authorization
medium
The Vitepos plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.
- CVSS:
- 4.3
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.2
- Disclosed:
- Apr 25, 2024
CVE-2024-33574 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database