Tag
#WooCommerce
blogHIGH 7.2
CVE-2026-17581: Code Injection Vulnerability in WCPOS – Point of Sale (POS) plugin for WooCommerce
The WCPOS – Point of Sale (POS) plugin for WooCommerce is vulnerable to code injection via the 'thermal' template engine. Authenticated attackers with Shop Manager-level access can inject arbitrary PHP code, leading to remote code execution on the server. This vulnerability has a CVSS score of 7.2 and is classified as CWE-94.
blogMEDIUM 6.5
Understanding and Defending Against CVE-2026-12973: Unauthorized Disclosure and Modification of WooCommerce Order Status
CVE-2026-12973 is a vulnerability in the PayPlus Payment Gateway WordPress plugin that allows unauthenticated users to disclose secret order keys and modify order statuses. This vulnerability has a CVSS score of 6.5 and is considered medium severity. It is not currently being actively exploited in the wild.