VYPR

WCPOS – Point of Sale (POS) plugin for WooCommerce

by WordPress

CVEs (2)

  • CVE-2026-17581HigAug 16, 2026
    risk 0.47cvss 7.2epss

    The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 'thermal' Template Engine in all versions up to, and including, 1.9.14 due to the Receipt_Renderer_Factory dispatching templates with the 'thermal' engine to the…

  • CVE-2026-16078MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.01

    The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access…