CVE-2026-14238 PUBLISHED

Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report

Assigner: WPScan
Reserved: 30.06.2026 Published: 10.08.2026 Updated: 10.08.2026

The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body before using it in a database query in one of its report endpoints, allowing users with administrator-level access to perform SQL injection.

Product Status

Vendor Unknown
Product vitepos
Versions Default: unaffected
  • affected from 0 to 3.6.0 (excl.)

Credits

  • Real_King_Engine (ISAL FRAMEWORK) finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE