Impact
The Vitepos WordPress plugin versions before 3.6.0 do not perform a per‑target authorization check in their point‑of‑sale password‑reset API. This flaw grants users with the custom Outlet Manager role an overly broad capability to reset any user’s password, including that of site administrators. Consequently, an attacker who can become an Outlet Manager can take control of any account, compromising the confidentiality, integrity, and availability of the entire site.
Affected Systems
The affected product is the Vitepos WordPress plugin. Versions prior to 3.6.0, and an earlier subset of versions prior to 3.5.0, are vulnerable. These plugin releases are integrated into WordPress‑based websites where the Outlet Manager role exists.
Risk and Exploitability
Once the user has the Outlet Manager role, the attacker can call the password‑reset API without further authorization, enabling them to reset any account password. The exploit requires no additional attacker privileges beyond that role, making it a low‑effort privilege escalation. No exploit probability is available from EPSS, and the vulnerability is not currently listed in the CISA KEV catalog. The severity of the flaw is high because it allows complete takeover of administrator accounts and any other site users’ credentials.
OpenCVE Enrichment