Junglewise Threat Intelligence

CVE-2026-14238: Vitepos SQL injection in product-details-report

CVE-2026-14238 · Severity: medium · CVSS 4.1 · Published 2026-08-10

Technologies: Vitepos. Vendors: Vitepos.

Executive brief

The Vitepos WordPress plugin, used for point-of-sale and inventory management in WooCommerce stores, contains a SQL injection vulnerability in its report API that allows site administrators to execute arbitrary SQL commands and potentially extract, modify, or delete sensitive database records. Exploitation requires valid WordPress administrator credentials and active WooCommerce integration.

Technical details

The vulnerability is a SQL injection (CWE-89) in the product-details-report REST endpoint that accepts an unsanitized "id" parameter from the JSON request body and passes it directly into a database query without parameterization. An authenticated administrator can inject SQL payloads via the /wp-json/vitepos/v1/report/product-details-report POST endpoint; time-based blind SQL injection has been confirmed via SLEEP() queries. The vulnerability is present only in the Pro build (not the Lite/free version) and requires WooCommerce to be active. A patch is available in version 3.6.0.

Affected products

  • Vitepos Vitepos before 3.6.0

Timeline

  • 2026-08-07: disclosed
  • 2026-08-10: patched: Fixed in version 3.6.0

References

Related threats