CVE-2026-17581
7.2WordPress · WCPOS – Point of Sale (POS) plugin for WooCommerce
The WCPOS plugin for WooCommerce is vulnerable to code injection via the thermal template engine, allowing authenticated administrators to execute arbitrary code on the underlying server.
Executive summary
A critical code injection vulnerability in the WCPOS plugin for WooCommerce permits authenticated attackers to achieve remote code execution, posing a severe risk to WordPress site integrity.
Vulnerability
The plugin contains a code injection flaw within the thermal template engine. This vulnerability requires high privileges (authenticated administrator) to exploit, allowing an attacker to execute arbitrary code through crafted input.
Business impact
Successful exploitation of this vulnerability grants an attacker full control over the WordPress application. This can lead to complete site compromise, unauthorized access to customer data, potential exfiltration of sensitive information, and significant reputational damage to the business. With a CVSS score of 7.2, the risk is classified as High, necessitating immediate attention.
Remediation
Immediate Action: Update the WCPOS – Point of Sale (POS) plugin to version 1.9.15 or later immediately.
Proactive Monitoring: Review administrative user logs for suspicious activity or unauthorized changes to template configurations.
Compensating Controls: Ensure a Web Application Firewall (WAF) is active to block malicious requests directed at template rendering functions.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This high-severity vulnerability presents a direct path to server-side code execution for authenticated users. Administrators must prioritize updating the plugin to version 1.9.15 to eliminate the injection vector and secure the WordPress environment against potential takeover.