CVE-2026-17581: Code Injection Vulnerability in WCPOS – Point of Sale (POS) plugin for WooCommerce
The WCPOS – Point of Sale (POS) plugin for WooCommerce is vulnerable to code injection via the 'thermal' template engine. Authenticated attackers with Shop Manager-level access can inject arbitrary PHP code, leading to remote code execution on the server. This vulnerability has a CVSS score of 7.2 and is classified as CWE-94.