PT-2026-69342 · WordPress · Vitepos
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
vitepos WordPress plugin versions prior to 3.6.0
Description
The point-of-sale password-reset API does not perform a per-target authorization check. Additionally, the custom Outlet Manager role is granted excessive password-reset capabilities by default. This allows a user with the Outlet Manager role to reset the password of any other user, including administrators, leading to full account takeover.
Recommendations
Update the vitepos WordPress plugin to version 3.6.0 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vitepos