Input validation vulnerability in WooCommerce Point Of Sale (POS) 1.4

The WooCommerce Point Of Sale (POS) plugin for WordPress is at risk of being hacked through a technique called SQL Injection. This can happen in versions 1.4 and below because the plugin does not properly protect against user input and does not adequately prepare for SQL queries. This means that someone who is logged in and has at least subscriber-level access can add their own malicious SQL queries to the existing ones, which could result in sensitive information being stolen from the website’s database.

Detected in:

WooCommerce Point Of Sale (POS) open vulnerable versions: >= * <= 1.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.