WordPress security by component
Oliver POS – A WooCommerce Point of Sale (POS)
Plugin description
Oliver POS – A WooCommerce Point of Sale (POS) is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published May 20, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
oliver-posLatest vulnerability
CVE-2026-6072: Oliver POS – A WooCommerce Point of Sale (POS): A security weakness
Oliver POS – A WooCommerce Point of Sale (POS) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.4.2.6.
| Safe version |
|
||
|---|---|---|---|
| May 20, 2026 |
CVE-2026-6072
Oliver POS – A WooCommerce Point of Sale (POS): A security weakness
Oliver POS – A WooCommerce Point of Sale (POS) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.4.2.6.
|
> 2.4.2.6 |
CVE6.5
NVDPending
|
| Feb 15, 2025 |
CVE-2024-13513
Oliver POS – A WooCommerce Point of Sale (POS): Sensitive information exposure
Oliver POS – A WooCommerce Point of Sale (POS) is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Feb 29, 2024 |
CVE-2024-0702
Oliver POS – A WooCommerce Point of Sale (POS): A security weakness
Oliver POS – A WooCommerce Point of Sale (POS) is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.3
NVDPending
|
| Feb 28, 2024 |
CVE-2024-1954
Oliver POS – A WooCommerce Point of Sale (POS): Cross-site request forgery
Oliver POS – A WooCommerce Point of Sale (POS) is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.3
NVDPending
|