← WordPress Vulnerabilities
WordPress security by component

Vitepos

Vitepos is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Jul 13, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: vitepos-lite

CVE-2026-57385: Vitepos: SQL injection

Vitepos is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 3.4.2.

PublishedJul 13, 2026
Known safe version3.4.3
Safe version
Jul 13, 2026 CVE-2026-57385
Vitepos: SQL injection
Vitepos is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 3.4.2.
3.4.3
CVE8.5
NVDPending
Jun 25, 2026 CVE-2026-54841
Vitepos: A security weakness
Vitepos is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.4.2.
3.4.3
CVE7.5
NVDPending
Apr 17, 2025 CVE-2025-39535
Vitepos: Privilege escalation or authentication bypass
Vitepos is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE7.2
NVDPending
Apr 01, 2025 CVE-2025-22277
Vitepos: Privilege escalation or authentication bypass
Vitepos is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Feb 22, 2025 CVE-2025-26750
Vitepos: A security weakness
Vitepos is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
May 08, 2024 CVE-2024-33574
Vitepos: A security weakness
Vitepos is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending