Vitepos – Point of Sale (POS) for WooCommerce
Vitepos – Point of Sale (POS) for WooCommerce has 8 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 8 are fixed as of September 2026. Their average CVSS score is 5.7, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2025 was the busiest year with 4 disclosures.
The most common weakness is Missing Authorization, behind 4 of the records (50%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Incorrect Privilege Assignment.
Every one of the 8 issues recorded for Vitepos – Point of Sale (POS) for WooCommerce has a vendor fix available, so running the current release closes all known holes.
6 independent researchers contributed these findings, most of them (2) reported by Phat RiO. Vitepos – Point of Sale (POS) for WooCommerce is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-13156Vitepos – Point of Sale (POS) for WooCommerce <= 3.3.0 - Authenticated (Subscriber+) Arbitrary File Upload to Remote Code Execution
Read the full analysisVulnerability Records

Vitepos – Point of Sale (POS) for WooCommerce
Author
appsbd
Vitepos is a lightning-fast and fully responsive Point of Sale (POS) plugin built for WooCommerce. Developed with the latest web technologies and following WooCommerce coding standards, it brings a seamless POS experience to your online or physical store. You can manage outlets, counters, customers, invoices, roles, and much more — all from one place. Vitepos supports barcode scanning, offline order processing, split payments, and complete role-based access control. Key Highlights – 👨💼 Role Management: Create roles (Cashier, Manager, etc.) and assign custom permissions. – 🏪 Outlets & Counters: Manage multiple outlets and assign cashiers per counter. – 🧾 Custom Invoices: Customize invoice layout and design as you wish. – 💳 Flexible Login: Use WordPress login or Vitepos built-in login. – 📦 Add Products from POS: Quickly create and manage products directly from the POS. – 🏷️ Barcode Support: Use scanners or mobile camera for barcode scanning. – 💰 Cash Drawer & Hold Cart: Manage cash drawers and temporarily hold customer carts. – 🌐 Offline Mode: Continue selling even without internet — data syncs automatically. – 💬 Multi-language Support: Works with Loco Translate and supports multiple languages. Intro Video: Quick Install: Full Playlist: https://www.youtube.com/playlist?list=PLYrwO-EqSMNuCHzUqp4Znan9mqa8sg-8V Features Customer Management: Add or search customers from the POS panel. Quick Add Products: Instantly create new products with variations. REST API Based: Built as a single-page application for lightning speed. Barcode Scanning: Scan products using a barcode device or your mobile camera. Dynamic Inventory Sync: Ensures no overselling by updating inventory in real-time. Print Receipts & Invoices: Auto or manual print with custom branding. Discounts, Fees & Notes: Apply discounts and add notes at checkout. Offline Mode: Continue operating POS even when the internet disconnects. Split Payment (Pro): Accept multiple payment methods in one order. Outlet & Counter Management: Unlimited outlets and counters. Cash Drawer: Manage drawer open/close and balances. Vendor & Purchase Module: Manage vendors and record purchases. Tax Calculation: Tax applied based on outlet location. Barcode Generator: Generate and print barcodes. User Access Control: Secure ACL-based permission management. Shortcuts: Keyboard shortcuts for faster workflow. Multi-Color Themes (Pro): Choose a color skin that fits your brand. Offline Order (Pro): Process offline orders easily. Responsive UI: Works perfectly on mobile, tablet, and desktop. JavaScript Source Vitepos frontend (Vue.js based) source code is available here: https://github.com/appsbd/vitepos-js External Service Disclosure This plugin connects to the following external services: Service: addon.appsbd.com Purpose: Fetches data about available plugin addons and related functionalities. Service: Google reCAPTCHA Purpose: Used for spam protection and user verification in the POS frontend. The reCAPTCHA API is loaded from https://www.google.com/recaptcha/api.js and may use cookies or tracking as per Google’s Privacy Policy.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C