What is CVE-2026-16078?
CVE-2026-16078 is a Directory Traversal vulnerability in the WCPOS – Point of Sale (POS) plugin for WooCommerce, affecting all versions up to 1.9.8. The flaw in the 'type' parameter allows authenticated attackers with shop manager-level access and above to read sensitive files on the server. It is recommended to update the plugin to the latest version immediately.
Azərbaycanca: CVE-2026-16078, WooCommerce üçün WCPOS – Point of Sale plugin-in 1.9.8-ə qədər olan bütün versiyalarında aşkarlanan Directory Traversal zəifliyidir. Bu zəiflik 'type' parametri vasitəsilə shop manager səviyyəsində autentifikasiya olunmuş hücumçulara serverdəki həssas faylları oxumağa imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of the WCPOS – Point of Sale plugin are affected by CVE-2026-16078?
All versions up to 1.9.8 are affected.
What privilege level is required to exploit CVE-2026-16078?
The vulnerability can be exploited by attackers authenticated at the shop manager level and above.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.