Extension WordPress
Vulnérabilités Vitepos – Point of Sale (POS) for WooCommerce
Cette page rassemble les failles publiées pour Vitepos – Point of Sale (POS) for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Vitepos – Point of Sale (POS) for WooCommerce
8 fiches
Vitepos – Point of Sale (POS) for WooCommerce <= 3.4.2 – Authenticated (Cashier+) SQL Injection
The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-3.4.2
3.4.3
07/07/2026
Vitepos – Point of Sale (POS) for WooCommerce <= 3.4.2 – Unauthenticated Information Exposure
The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.2. This makes it possible for unauthenticated attackers to extract sensitive user or…
*-3.4.2
3.4.3
18/06/2026
Vitepos – Point of Sale (POS) for WooCommerce < 3.4.2 – Authenticated (Outlet Manager+) Privilege Escalation
The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 3.4.2 (exclusive). This makes it possible for authenticated attackers, with Outlet Manager-level access and above, to…
[*, 3.4.2)
3.4.2
01/06/2026
Vitepos – Point of Sale (POS) for WooCommerce <= 3.3.0 – Authenticated (Subscriber+) Arbitrary File Upload to Remote Code Execution
The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the insert_media_attachment() function in all versions up to, and including, 3.3.0. This is…
*-3.3.0
3.3.1
20/11/2025
Vitepos <= 3.1.7 – Missing Authorization
The Vitepos – Point of sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.7. This makes it…
*-3.1.7
3.1.8
17/04/2025
Vitepos <= 3.1.4 – Missing Authorization
The Vitepos – Point of sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.4. This makes it…
*-3.1.4
3.1.5
31/03/2025
Vitepos – Point of sale (POS) <= 3.1.3 – Missing Authorization
The Vitepos – Point of sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.3. This makes it…
*-3.1.3
3.1.4
14/02/2025
Vitepos <= 3.0.1 – Missing Authorization
The Vitepos plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-3.0.1
3.0.2
25/04/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.