All 3 CVE vulnerabilities found in WCPOS – Point of Sale (POS) plugin for WooCommerce, with AI-generated Chinese analysis, references, and POCs.
Vendor: kilbot
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-17581 | WCPOS <= 1.9.14 - Authenticated (Shop Manager+) Code Injection via 'thermal' Template Engine CWE-94 | 7.2 | High | 2026-08-16 |
| CVE-2026-16078 | WCPOS <= 1.9.8 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read via 'type' Parameter CWE-22 | 6.5 | Medium | 2026-07-23 |
| CVE-2024-2384 | WooCommerce POS <= 1.4.11 - Insufficient Verification of Data Authenticity to Authenticated (Customer+) Information Disclosure CWE-345 | 4.3 | Medium | 2024-03-20 |
All 3 known CVE vulnerabilities affecting WCPOS – Point of Sale (POS) plugin for WooCommerce with full Chinese analysis, references, and POCs where available.