Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Appsbd Vitepos vitepos-lite allows Blind SQL Injection.This issue affects Vitepos: from n/a through 3.6.1.
Published: 2026-10-08
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: SQL Injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an SQL Injection flaw caused by improper neutralization of special elements in the Vitepos Lite WordPress plugin, allowing an attacker to inject SQL commands into database queries. This can enable an attacker to read sensitive data, and in some cases modify or delete records, leading to significant confidentiality and integrity compromise. The weakness is identified as CWE-89 and is considered a blind injection, implying that attackers may not see immediate response outputs but can infer the database structure and contents through query results or timing differences.

Affected Systems

The flaw exists in Appsbd Vitepos Lite versions up to 3.6.1. Any WordPress instance that has the Vitepos Lite plugin installed within that version range is vulnerable. All releases from the initial release (“n/a”) through 3.6.1 are affected.

Risk and Exploitability

The CVSS score of 7.6 places this issue in the high severity category. No EPSS score is publicly available, so the current exploitation probability cannot be quantified, but the lack of KEV listing suggests no widespread public exploitation at this time. The likely attack surface is via HTTP requests to the plugin’s endpoints that accept user-supplied parameters without proper sanitization. An attacker with network access to the WordPress site can craft malicious requests to the vulnerable API or form submission and trigger blind SQL queries that return or manipulate data. If the WordPress installation allows anonymous or unauthenticated access to the Vitepos endpoints, the attack requires no privilege escalation. However, even with limited access, the ability to extract or alter data can have severe operational impacts.

Generated by OpenCVE AI on October 8, 2026 at 14:23 UTC.

Remediation

Vendor Solution

Update the WordPress Vitepos plugin to the latest available version (at least 3.6.2).


OpenCVE Recommended Actions

  • Upgrade the Vitepos Lite plugin to version 3.6.2 or later, which contains the SQL sanitization fix.
  • If an upgrade cannot be applied immediately, restrict access to the Vitepos admin and front‑end endpoints to trusted IP addresses or enforce strong authentication to limit exposure of the vulnerable input vectors.
  • Perform a comprehensive security review of the entire WordPress installation, scanning for other unsanitized database queries or outdated plugins, and monitor error logs for patterns indicative of SQL injection attempts.

Generated by OpenCVE AI on October 8, 2026 at 14:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Appsbd Vitepos vitepos-lite allows Blind SQL Injection.This issue affects Vitepos: from n/a through 3.6.1.
Title WordPress Vitepos plugin <= 3.6.1 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-08T12:56:45.331Z

Reserved: 2026-10-03T00:17:03.679Z

Link: CVE-2026-105076

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T13:17:12.763

Modified: 2026-10-08T13:17:12.763

Link: CVE-2026-105076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T14:30:18Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')