WCPOS <= 1.9.14 - Authenticated (Shop Manager+) Code Injection via 'thermal' Template Engine
high
The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 'thermal' Template Engine in all versions up to, and including, 1.9.14 due to the Receipt_Renderer_Factory dispatching templates with the 'thermal' engine to the Legacy_Php_Renderer instead of a safe ther...
- CVSS:
- 7.2
- Affected:
- up to 1.9.14
- Fixed in:
- 1.9.15
- Disclosed:
- Aug 15, 2026
CVE-2026-17581 on NVD →
WCPOS <= 1.9.8 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read via 'type' Parameter
medium
The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access and above, to read the contents of arbitrary...
- CVSS:
- 6.5
- Affected:
- up to 1.9.8
- Fixed in:
- 1.9.9
- Disclosed:
- Jul 22, 2026
CVE-2026-16078 on NVD →
WCPOS – Point of Sale (POS) plugin for WooCommerce <= 1.8.14 - Missing Authorization
medium
The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.8.14. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.8.14
- Fixed in:
- 1.9.0
- Disclosed:
- Jun 15, 2026
CVE-2026-52711 on NVD →
WooCommerce POS <= 1.7.8 - Missing Authorization
medium
The WooCommerce POS – Point of Sale plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.9
- Disclosed:
- May 16, 2025
CVE-2025-48117 on NVD →
WooCommerce POS – Point of Sale [woocommerce-pos] <= 1.7.8 (unfixed)
unknown
[en] Missing Authorization vulnerability in kilbot WooCommerce POS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WooCommerce POS: from n/a through 1.7.8.
- Affected:
- up to 1.7.8
- Fix:
- No patched version reported
- Disclosed:
- May 16, 2025
CVE-2025-48117 on NVD →
WooCommerce POS – Point of Sale [woocommerce-pos] < 1.4.12
unknown
[en] The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the authentication and authorization of the current user This makes it possible for authenticated attackers, with customer-level access and...
- Affected:
- up to 1.4.12
- Fixed in:
- 1.4.12
- Disclosed:
- Mar 20, 2024
CVE-2024-2384 on NVD →
WooCommerce POS <= 1.4.11 - Insufficient Verification of Data Authenticity to Authenticated (Customer+) Information Disclosure
medium
The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the authentication and authorization of the current user This makes it possible for authenticated attackers, with customer-level access and abov...
- CVSS:
- 4.3
- Affected:
- up to 1.4.11
- Fixed in:
- 1.4.12
- Disclosed:
- Mar 19, 2024
CVE-2024-2384 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database