Software intelligence
Important: Vitepos Lite appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works
Tracked advisories
8
Latest advisory
7 July 2026
CISA KEV matches
0
In this WordPress feed
WordPress slug
vitepos-lite
Plugin
This catalog lists 8 known advisories affecting Vitepos Lite. The most recent was published on 7 July 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.
Vitepos – Point of Sale (POS) for WooCommerce <= 3.4.2 - Authenticated (Cashier+) SQL Injection
May allow attackers to read or modify database contents beyond intended access.
Published 7 July 2026
Vitepos – Point of Sale (POS) for WooCommerce <= 3.4.2 - Unauthenticated Information Exposure
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Published 18 June 2026
Vitepos – Point of Sale (POS) for WooCommerce < 3.4.2 - Authenticated (Outlet Manager+) Privilege Escalation
May allow a lower-privilege user to perform actions reserved for administrators.
Published 1 June 2026
Known Vitepos Lite advisories published by month.
CVE-2026-57385 · Published 7 July 2026
Affected versions: ≤ 3.4.2
CVE-2026-54841 · Published 18 June 2026
Affected versions: ≤ 3.4.2
CVE-2026-8157 · Published 1 June 2026
Affected versions: < 3.4.2
CVE-2025-13156 · Published 20 November 2025
Affected versions: ≤ 3.3.0
CVE-2025-39535 · Published 17 April 2025
Affected versions: ≤ 3.1.7
CVE-2025-22277 · Published 31 March 2025
Affected versions: ≤ 3.1.4
CVE-2025-26750 · Published 14 February 2025
Affected versions: ≤ 3.1.3
CVE-2024-33574 · Published 25 April 2024
Affected versions: ≤ 3.0.1
SiteRespond Defence matches your installed Vitepos Lite version against this catalog when the Defence plugin is connected to your WordPress site.