Code Injection Vulnerability in WCPOS Plugin for WooCommerce
CVE-2026-17581
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2026
What is CVE-2026-17581?
The WCPOS โ Point of Sale (POS) plugin for WooCommerce exposes a critical security vulnerability that enables code injection via the 'thermal' Template Engine. This flaw exists in all versions up to and including 1.9.14, where the Receipt_Renderer_Factory improperly dispatches templates to the Legacy_Php_Renderer instead of utilizing a dedicated and secure thermal renderer. Consequently, this oversight allows authenticated users with Shop Manager-level access or higher to inject arbitrary PHP code into a template post. The malicious code can be executed through PHPโs include() function once written to a temporary file, leading to potential remote code execution on the server.
Affected Version(s)
WCPOS โ Point of Sale (POS) plugin for WooCommerce 0 <= 1.9.14