Summary
CVE-2026-54841 is a high-severity Unauthenticated Sensitive Data Exposure vulnerability in the Vitepos – Point of Sale (POS) for WooCommerce WordPress plugin by Appsbd, affecting all versions up to and including 3.4.2. With a CVSS v3.1 base score of 7.5 (HIGH), the flaw allows any unauthenticated remote attacker to retrieve sensitive information without any privileges or user interaction. A patched version is available and immediate upgrading is strongly recommended.
Technical details
- Root cause: Classified as CWE-201 (Insertion of Sensitive Information Into Sent Data) — the plugin exposes sensitive data within transmitted responses in a manner accessible to unauthenticated network requesters.
- Trigger conditions: No authentication, no user interaction, and no special configuration are required to trigger the vulnerability; an attacker only needs network access to the affected WordPress site.
- Attack vector: Remotely exploitable over the network (AV:N), with low attack complexity (AC:L), no privileges required (PR:N), and no user interaction (UI:N).
- Impact: High confidentiality impact (C:H) with no integrity or availability impact. Sensitive data processed or transmitted by the Vitepos plugin — which handles WooCommerce point-of-sale operations including order records, customer data, and POS session information — may be exposed to unauthenticated attackers.
Affected software
- Vitepos – Point of Sale (POS) for WooCommerce (
vitepos-lite) by Appsbd — all versions <= 3.4.2
Severity
- CVSS v3.1 Base Score: 7.5 (HIGH)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Upgrade Vitepos to version 3.4.3 or later. Version 3.4.4 is the latest release currently available in the WordPress Plugin Repository and contains the security fix.
- Verify the installed plugin version via the WordPress admin dashboard under Plugins → Installed Plugins and apply any pending updates without delay.
- If an immediate upgrade is not possible, consider temporarily deactivating the plugin and restricting access to the WordPress site’s REST API endpoints from untrusted networks as a temporary mitigation until patching can be completed.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

