plugin

Woocommerce Openpos Vulnerabilities

6 known security issues reported for the Woocommerce Openpos WordPress plugin. Most recent disclosed Aug 13, 2024.

2 critical 1 medium

Running Woocommerce Openpos on your site? Check whether your installed version is affected.

Scan your site free

Openpos [woocommerce-openpos] < 7.0.2

unknown

[en] Missing Authorization vulnerability in anhvnit Woocommerce OpenPos allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Woocommerce OpenPos: from n/a through 6.4.4.

Affected:
up to 7.0.2
Fixed in:
7.0.2
Disclosed:
Aug 13, 2024

CVE-2024-37935 on NVD →

Openpos [woocommerce-openpos] < 7.0.1

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in anhvnit Woocommerce OpenPos allows File Manipulation.This issue affects Woocommerce OpenPos: from n/a through 6.4.4.

Affected:
up to 7.0.1
Fixed in:
7.0.1
Disclosed:
Jul 12, 2024

CVE-2024-37932 on NVD →

Openpos [woocommerce-openpos] < 7.0.1

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in anhvnit Woocommerce OpenPos.This issue affects Woocommerce OpenPos: from n/a through 6.4.4.

Affected:
up to 7.0.1
Fixed in:
7.0.1
Disclosed:
Jul 12, 2024

CVE-2024-37933 on NVD →

Woocommerce OpenPos <= 6.4.4 - Unauthenticated SQL Injection

critical

The Woocommerce OpenPos plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL que...

CVSS:
10
Affected:
up to 6.4.4
Fixed in:
7.0.1
Disclosed:
Jul 9, 2024

CVE-2024-37933 on NVD →

Woocommerce OpenPos <= 6.4.4 - Unauthenticated Arbitrary File Deletion

critical

The Openpos - WooCommerce Point Of Sale(POS) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 6.4.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily le...

CVSS:
9.1
Affected:
up to 6.4.4
Fixed in:
7.0.1
Disclosed:
Jul 9, 2024

CVE-2024-37932 on NVD →

Woocommerce OpenPos <= 7.0.1 - Missing Authorization to Information Exposure

medium

The Woocommerce OpenPos plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on a function in versions up to, and including, 7.0.1. This makes it possible for unauthenticated attackers to view sensitive information.

CVSS:
5.3
Affected:
up to 7.0.1
Fixed in:
7.0.2
Disclosed:
Jul 9, 2024

CVE-2024-37935 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database