plugin

Woocommerce Pos Vulnerabilities

7 known security issues reported for the Woocommerce Pos WordPress plugin. Most recent disclosed Aug 15, 2026.

1 high 4 medium

Running Woocommerce Pos on your site? Check whether your installed version is affected.

Scan your site free

WCPOS <= 1.9.14 - Authenticated (Shop Manager+) Code Injection via 'thermal' Template Engine

high

The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 'thermal' Template Engine in all versions up to, and including, 1.9.14 due to the Receipt_Renderer_Factory dispatching templates with the 'thermal' engine to the Legacy_Php_Renderer instead of a safe ther...

CVSS:
7.2
Affected:
up to 1.9.14
Fixed in:
1.9.15
Disclosed:
Aug 15, 2026

CVE-2026-17581 on NVD →

WCPOS <= 1.9.8 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read via 'type' Parameter

medium

The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access and above, to read the contents of arbitrary...

CVSS:
6.5
Affected:
up to 1.9.8
Fixed in:
1.9.9
Disclosed:
Jul 22, 2026

CVE-2026-16078 on NVD →

WCPOS – Point of Sale (POS) plugin for WooCommerce <= 1.8.14 - Missing Authorization

medium

The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.8.14. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.8.14
Fixed in:
1.9.0
Disclosed:
Jun 15, 2026

CVE-2026-52711 on NVD →

WooCommerce POS <= 1.7.8 - Missing Authorization

medium

The WooCommerce POS – Point of Sale plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.7.8
Fixed in:
1.7.9
Disclosed:
May 16, 2025

CVE-2025-48117 on NVD →

WooCommerce POS &#8211; Point of Sale [woocommerce-pos] <= 1.7.8 (unfixed)

unknown

[en] Missing Authorization vulnerability in kilbot WooCommerce POS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WooCommerce POS: from n/a through 1.7.8.

Affected:
up to 1.7.8
Fix:
No patched version reported
Disclosed:
May 16, 2025

CVE-2025-48117 on NVD →

WooCommerce POS &#8211; Point of Sale [woocommerce-pos] < 1.4.12

unknown

[en] The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the authentication and authorization of the current user This makes it possible for authenticated attackers, with customer-level access and...

Affected:
up to 1.4.12
Fixed in:
1.4.12
Disclosed:
Mar 20, 2024

CVE-2024-2384 on NVD →

WooCommerce POS <= 1.4.11 - Insufficient Verification of Data Authenticity to Authenticated (Customer+) Information Disclosure

medium

The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the authentication and authorization of the current user This makes it possible for authenticated attackers, with customer-level access and abov...

CVSS:
4.3
Affected:
up to 1.4.11
Fixed in:
1.4.12
Disclosed:
Mar 19, 2024

CVE-2024-2384 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database