CVE-2026-105076: WordPress Vitepos plugin <= 3.6.1 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Appsbd Vitepos vitepos-lite allows Blind SQL Injection.This issue affects Vitepos: from n/a through 3.6.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Vitepos pluginto a version that resolves this vulnerability.Fixed in 3.6.2
Event History
Frequently Asked Questions
Which installations should be treated as affected?
WordPress sites using the Appsbd Vitepos plugin should be treated as affected if they run version 3.6.1 or any earlier version. The available data does not identify an unaffected fixed version.
What does an attacker need to exploit this issue?
The attacker must already have high-level privileges, according to the PR:H metric. The attack can be performed over the network and does not require user interaction.
What is the likely security impact?
The vulnerability can enable blind SQL injection with high confidentiality impact and low availability impact. The supplied metrics indicate no direct integrity impact, but the scope may extend beyond the vulnerable component.