{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-17581/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-17581"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WCPOS – Point of Sale (POS) plugin for WooCommerce"],"_cs_severities":["high"],"_cs_tags":["wordpress","rce","web-application","cve-2026-17581"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe WCPOS - Point of Sale (POS) plugin for WooCommerce (versions 1.9.14 and earlier) contains a critical remote code execution (RCE) vulnerability identified as CVE-2026-17581. The flaw exists within the 'thermal' template engine, where the Receipt_Renderer_Factory incorrectly dispatches thermal templates to the Legacy_Php_Renderer. This improper handling allows an authenticated user with 'Shop Manager' privileges or higher to inject arbitrary PHP code into a template post. When saved, this template is written to a temporary file and subsequently executed via a PHP include() statement. Because this requires Shop Manager privileges, the attack vector is likely to be utilized by compromised accounts or malicious insiders rather than unauthenticated external actors.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains access to a WordPress account with 'Shop Manager' or administrator level privileges.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates to the WordPress dashboard.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the WCPOS plugin template management interface.\u003c/li\u003e\n\u003cli\u003eAttacker submits a POST request containing malicious PHP code within the template editor under the 'thermal' template engine settings.\u003c/li\u003e\n\u003cli\u003eThe plugin performs a nonce check (wcpos_template_settings) and permission check (manage_woocommerce_pos).\u003c/li\u003e\n\u003cli\u003eThe Receipt_Renderer_Factory receives the request and misroutes the 'thermal' template to the Legacy_Php_Renderer.\u003c/li\u003e\n\u003cli\u003eThe application writes the malicious payload to a temporary file on the web server's local file system.\u003c/li\u003e\n\u003cli\u003eThe application calls include() on the generated temporary file, leading to server-side code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full remote code execution on the WordPress host server, granting the attacker the ability to execute arbitrary commands, access database credentials, exfiltrate site data, or install persistent web shells. The impact is limited to environments where the attacker can obtain authenticated access to a Shop Manager account or higher.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the WCPOS - Point of Sale (POS) plugin for WooCommerce to version 1.9.15 or later to patch the template rendering logic.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user roles to identify and restrict accounts with 'Shop Manager' capabilities.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests to WCPOS plugin endpoints from authenticated administrative sessions.\u003c/li\u003e\n\u003cli\u003eReview site file integrity for unexpected PHP files created within the WordPress temporary directory paths.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-16T06:25:04Z","date_published":"2026-08-16T06:25:04Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wcpos-rce/","summary":"The WCPOS plugin for WooCommerce is vulnerable to authenticated remote code execution via a template engine misconfiguration that allows injection and execution of arbitrary PHP code.","title":"Authenticated Remote Code Execution in WCPOS WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-wcpos-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-17581","version":"https://jsonfeed.org/version/1.1"}