Junglewise Threat Intelligence

CVE-2026-16078: kilbot WCPOS Directory Traversal in Templates_Controller

CVE-2026-16078 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Executive brief

The WCPOS plugin for WooCommerce, which provides point-of-sale functionality for WordPress sites, contains a security flaw that allows authorized users with shop manager access to view private files on the server. By exploiting this vulnerability, an attacker could steal sensitive configuration files or system data, potentially leading to further compromise of the website. This issue affects all versions of the plugin up to and including 1.9.8.

Technical details

A directory traversal vulnerability exists in the WCPOS plugin due to insufficient validation of the 'type' parameter within the Templates_Controller. An authenticated attacker with at least Shop Manager privileges can exploit this by sending a crafted REST API request. By including 'context=edit' in the request, the attacker can bypass the content-stripping logic in the prepare_item_for_response() function, causing the server to return the contents of arbitrary files verbatim. The vulnerability is present in all versions up to 1.9.8 and was addressed in subsequent updates.

Affected products

  • kilbot WCPOS – Point of Sale (POS) plugin for WooCommerce up to, and including, 1.9.8

Timeline

  • 2026-07-23: advisory: NVD publication date
  • 2026-07-23: disclosed: Wordfence advisory published

References