Vitepos Point of Sale for WooCommerce Arbitrary File Upload Vulnerability Allowing Remote Code Execution
Vulnerability
A vulnerability exists in the Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress, in all versions through 3.3.0. The issue arises from inadequate file type validation in the insert_media_attachment() function, allowing authenticated users with subscriber-level access and above to upload arbitrary files. This vulnerability could lead to remote code execution on the affected site's server.
Impact
Exploitation of this vulnerability allows for arbitrary file uploads, which could be used to execute malicious code on the server, leading to remote code execution.
Remediation
Users are advised to update the Vitepos – Point of Sale (POS) for WooCommerce plugin to version 3.3.1 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
