What is CVE-2026-17581?
CVE-2026-17581 is a code injection vulnerability in the WCPOS – Point of Sale plugin for WordPress, affecting versions up to and including 1.9.14. The flaw occurs via the 'thermal' Template Engine due to improper dispatching in the Receipt_Renderer_Factory. Immediate plugin update is required to mitigate the risk.
Azərbaycanca: CVE-2026-17581, WordPress üçün WCPOS – Point of Sale pluginində aşkar edilmiş kod inyeksiyası zəifliyidir. 'thermal' Template Engine vasitəsilə baş verən bu problem, pluginin 1.9.14 və daha əvvəlki versiyalarına təsir edir. Plugin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which WordPress plugin is affected by CVE-2026-17581?
This vulnerability affects the WCPOS – Point of Sale plugin.
Through which component does CVE-2026-17581 occur?
The vulnerability occurs via the 'thermal' Template Engine.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.