← WordPress Vulnerabilities
WordPress security by component

Oliver POS – A WooCommerce Point of Sale (POS)

Oliver POS – A WooCommerce Point of Sale (POS) is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published May 20, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: oliver-pos

CVE-2026-6072: Oliver POS – A WooCommerce Point of Sale (POS): A security weakness

Oliver POS – A WooCommerce Point of Sale (POS) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.4.2.6.

PublishedMay 20, 2026
Known safe version> 2.4.2.6
Safe version
May 20, 2026 CVE-2026-6072
Oliver POS – A WooCommerce Point of Sale (POS): A security weakness
Oliver POS – A WooCommerce Point of Sale (POS) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.4.2.6.
> 2.4.2.6
CVE6.5
NVDPending
Feb 15, 2025 CVE-2024-13513
Oliver POS – A WooCommerce Point of Sale (POS): Sensitive information exposure
Oliver POS – A WooCommerce Point of Sale (POS) is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE9.8
NVDPending
Feb 29, 2024 CVE-2024-0702
Oliver POS – A WooCommerce Point of Sale (POS): A security weakness
Oliver POS – A WooCommerce Point of Sale (POS) is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.3
NVDPending
Feb 28, 2024 CVE-2024-1954
Oliver POS – A WooCommerce Point of Sale (POS): Cross-site request forgery
Oliver POS – A WooCommerce Point of Sale (POS) is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.3
NVDPending