PT-2026-69342 · WordPress · Vitepos

·

CVE-2026-14237

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vitepos WordPress plugin versions prior to 3.6.0
Description The point-of-sale password-reset API does not perform a per-target authorization check. Additionally, the custom Outlet Manager role is granted excessive password-reset capabilities by default. This allows a user with the Outlet Manager role to reset the password of any other user, including administrators, leading to full account takeover.
Recommendations Update the vitepos WordPress plugin to version 3.6.0 or later.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14237

Affected Products

Vitepos