plugin

Woo Point Of Sale Vulnerabilities

2 known security issues reported for the Woo Point Of Sale WordPress plugin. Most recent disclosed Dec 25, 2024.

1 critical

Running Woo Point Of Sale on your site? Check whether your installed version is affected.

Scan your site free

Point of Sale System for WooCommerce [woo-point-of-sale] < 6.2.0

unknown

[en] The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0. This is due to insufficient validation on the 'logged_in_user_id' value when option values are empty and the ability for attackers to change the email of arbitrary user accounts. Th...

Affected:
up to 6.2.0
Fixed in:
6.2.0
Disclosed:
Dec 25, 2024

CVE-2024-11281 on NVD →

WooCommerce Point of Sale <= 6.1.0 - Insecure Direct Object Reference to Privilege Escalation via Arbitrary User Email Change

critical

The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0. This is due to insufficient validation on the 'logged_in_user_id' value when option values are empty and the ability for attackers to change the email of arbitrary user accounts. This ma...

CVSS:
9.8
Affected:
up to 6.1.0
Fixed in:
6.2.0
Disclosed:
Dec 24, 2024

CVE-2024-11281 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database