Executive brief
WooCommerce POS is a WordPress plugin that allows store owners to manage physical point-of-sale transactions through their online store. A security flaw in versions 1.8.14 and earlier allows unauthorized individuals to bypass security checks and access sensitive information. This could lead to the exposure of customer or store data, potentially impacting business operations and privacy compliance.
Technical details
The WooCommerce POS plugin for WordPress (versions <= 1.8.14) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw over the network without any user interaction. The vulnerability allows for unauthorized access to sensitive information, as indicated by the high confidentiality impact in the CVSS vector. The issue is resolved in version 1.9.0.
Affected products
- WooCommerce POS WooCommerce POS <= 1.8.14
Timeline
- 2026-02-14: other: Reported by Nguyen Ba Khanh
- 2026-06-15: advisory: Patchstack advisory published
- 2026-06-16: disclosed: NVD publication date