CVE-2026-14238: Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report
Published Aug 10, 2026
·Updated
The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body before using it in a database query in one of its report endpoints, allowing users with administrator-level access to perform SQL injection.
Affected Software
1 affected component
Vitepos WordPress plugin<3.6.0
Event History
Aug 10, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-14238?
The severity of CVE-2026-14238 is rated as 46.
2
What type of vulnerability is CVE-2026-14238?
CVE-2026-14238 is an SQL Injection vulnerability affecting the Vitepos WordPress plugin.
3
How do I fix CVE-2026-14238?
To fix CVE-2026-14238, update the Vitepos WordPress plugin to version 3.6.0 or later.
4
Who can exploit CVE-2026-14238?
CVE-2026-14238 can be exploited by users with administrator-level access to the Vitepos WordPress plugin.
5
What impact does CVE-2026-14238 have on my website?
CVE-2026-14238 can allow unauthorized SQL injection, potentially compromising your WordPress database and sensitive information.