🔐 CVE Alert

CVE-2026-16078

MEDIUM 6.5

WCPOS <= 1.9.8 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read via 'type' Parameter

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. Successful exploitation requires supplying context=edit in the request, which bypasses the content-stripping logic in prepare_item_for_response() and returns the traversed file verbatim in the REST API response.

CWE CWE-22
Vendor kilbot
Product wcpos – point of sale (pos) plugin for woocommerce
Published Jul 23, 2026
Stay Ahead of the Next One

Get instant alerts for kilbot wcpos – point of sale (pos) plugin for woocommerce

Be the first to know when new medium vulnerabilities affecting kilbot wcpos – point of sale (pos) plugin for woocommerce are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

kilbot / WCPOS – Point of Sale (POS) plugin for WooCommerce
0 ≤ 1.9.8

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/0148c70f-38e4-43d9-994e-f2b01dd168a1?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/woocommerce-pos/tags/1.9.7/includes/API/Templates_Controller.php#L446 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/woocommerce-pos/tags/1.9.7/includes/Templates.php#L481 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/woocommerce-pos/tags/1.9.7/includes/Templates.php#L445 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/woocommerce-pos/tags/1.9.7/includes/API/Templates_Controller.php#L1497 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?reponame=&old=3612715%40woocommerce-pos&new=3612715%40woocommerce-pos

Credits

Wordfence PRISM