Executive brief
The Vitepos WordPress plugin, used for point-of-sale and inventory management in WooCommerce stores, contains a SQL injection vulnerability in its report API that allows site administrators to execute arbitrary SQL commands and potentially extract, modify, or delete sensitive database records. Exploitation requires valid WordPress administrator credentials and active WooCommerce integration.
Technical details
The vulnerability is a SQL injection (CWE-89) in the product-details-report REST endpoint that accepts an unsanitized "id" parameter from the JSON request body and passes it directly into a database query without parameterization. An authenticated administrator can inject SQL payloads via the /wp-json/vitepos/v1/report/product-details-report POST endpoint; time-based blind SQL injection has been confirmed via SLEEP() queries. The vulnerability is present only in the Pro build (not the Lite/free version) and requires WooCommerce to be active. A patch is available in version 3.6.0.
Affected products
- Vitepos Vitepos before 3.6.0
Timeline
- 2026-08-07: disclosed
- 2026-08-10: patched: Fixed in version 3.6.0