Executive brief
The POS Entegratör plugin for WordPress, which integrates point-of-sale systems with e-commerce sites, contains a security flaw that allows unauthorized individuals to perform administrative actions. An attacker could potentially modify payment settings or disrupt transaction processing without needing a password. This could lead to financial discrepancies, loss of customer trust, and operational downtime for online merchants.
Technical details
A broken access control vulnerability (CWE-862) exists in the POS Entegratör plugin for WordPress through version 3.7.103. The flaw stems from missing authorization checks or nonce validation in certain plugin functions, allowing an unauthenticated remote attacker to execute privileged actions. With a CVSS score of 8.2, the impact is primarily on integrity, as attackers can modify configurations or data without authentication. The issue is resolved in version 3.8.0.
Affected products
- Gurmehub (Gurme Yazılım) POS Entegratör <= 3.7.103
Timeline
- 2026-02-23: other: Reported by hivesec
- 2026-06-29: advisory: Patchstack advisory published
- 2026-07-02: disclosed: NVD published date
- 2026-07-02: patched: Version 3.8.0 released