Code Injection Vulnerability in WCPOS Plugin for WooCommerce
CVE-2026-17581

7.2HIGH

What is CVE-2026-17581?

The WCPOS โ€“ Point of Sale (POS) plugin for WooCommerce exposes a critical security vulnerability that enables code injection via the 'thermal' Template Engine. This flaw exists in all versions up to and including 1.9.14, where the Receipt_Renderer_Factory improperly dispatches templates to the Legacy_Php_Renderer instead of utilizing a dedicated and secure thermal renderer. Consequently, this oversight allows authenticated users with Shop Manager-level access or higher to inject arbitrary PHP code into a template post. The malicious code can be executed through PHPโ€™s include() function once written to a temporary file, leading to potential remote code execution on the server.

Affected Version(s)

WCPOS โ€“ Point of Sale (POS) plugin for WooCommerce 0 <= 1.9.14

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.