Executive brief
Vitepos is a Point of Sale (POS) plugin for WordPress used by businesses to manage sales and inventory. A security flaw in this plugin allows an attacker with basic store access, such as a cashier, to perform unauthorized database queries. This could lead to the theft of sensitive customer information, sales data, or other internal records, potentially disrupting business operations.
Technical details
A Blind SQL Injection vulnerability exists in the appsbd Vitepos (vitepos-lite) plugin for WordPress due to improper neutralization of special elements in SQL commands. The vulnerability is accessible to authenticated users with 'Cashier' level privileges. By sending specially crafted requests, an attacker can infer data from the database through blind techniques. The vulnerability has a CVSS 3.1 base score of 8.5, reflecting its potential for high confidentiality impact. The issue is fixed in version 3.4.3.
Affected products
- appsbd Vitepos (vitepos-lite) <= 3.4.2
Timeline
- 2026-04-19: disclosed: Reported by endy via Patchstack VDP
- 2026-07-07: advisory: Patchstack published advisory
- 2026-07-13: advisory: NVD published CVE-2026-57385
- 2026-07-07: patched: Version 3.4.3 released to address the issue