CVE-2025-13156: Vitepos – Point of Sale (POS) for WooCommerce <= 3.3.0 - Authenticated (Subscriber+) Arbitrary File Upload to Remote Code Execution
The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the insertmediaattachment() function in all versions up to, and including, 3.3.0. This is due to the saveupdatecategoryimg() function accepting user-supplied file types without validation when processing category images. This makes it possible for authenticated attackers, with subscriber level access and above, to upload arbitrary files on the affected site's server which makes remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13156?
CVE-2025-13156 has a moderate severity level due to the potential risk of arbitrary file uploads.
How do I fix CVE-2025-13156?
To fix CVE-2025-13156, update the Vitepos Point of Sale (POS) for WooCommerce plugin to version 3.3.1 or later.
Who is affected by CVE-2025-13156?
CVE-2025-13156 affects all versions of the Vitepos Point of Sale (POS) for WooCommerce plugin up to and including 3.3.0.
What is the impact of CVE-2025-13156?
The impact of CVE-2025-13156 includes the potential for attackers to upload unauthorized files to the server.
When was CVE-2025-13156 disclosed?
CVE-2025-13156 was disclosed in 2025, highlighting the vulnerabilities in earlier versions of the plugin.