Junglewise Threat Intelligence

CVE-2026-54841: Appsbd Vitepos sensitive data exposure

CVE-2026-54841 · Severity: high · CVSS 7.5 · Published 2026-06-25

Technologies: Appsbd Vitepos.

Executive brief

Vitepos, a Point of Sale (POS) plugin for WordPress, contains a security flaw that allows unauthorized individuals to access sensitive information. An attacker could exploit this to view data that should be restricted, potentially leading to further compromises of the website or business operations. This issue affects all versions up to 3.4.2 and can be resolved by updating to version 3.4.3.

Technical details

The Vitepos plugin (specifically the vitepos-lite package) for WordPress is vulnerable to an unauthenticated sensitive data exposure flaw (CWE-201). The vulnerability exists in versions up to and including 3.4.2. A remote, unauthenticated attacker can exploit this flaw via the network to access sensitive information that is normally restricted. This exposure is classified as high severity because it requires no privileges or user interaction and can facilitate further attacks against the host system. The issue is addressed in version 3.4.3.

Affected products

  • Appsbd Vitepos <= 3.4.2

Timeline

  • 2026-06-04: disclosed: Reported by qdtad via Patchstack
  • 2026-06-18: advisory: Patchstack published advisory
  • 2026-06-25: advisory: NVD published CVE-2026-54841
  • 2026-06-25: patched: Version 3.4.3 released to address the vulnerability

References