Description
The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.
Published: 2026-08-10
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Vitepos WordPress plugin versions before 3.6.0 do not perform a per‑target authorization check in their point‑of‑sale password‑reset API. This flaw grants users with the custom Outlet Manager role an overly broad capability to reset any user’s password, including that of site administrators. Consequently, an attacker who can become an Outlet Manager can take control of any account, compromising the confidentiality, integrity, and availability of the entire site.

Affected Systems

The affected product is the Vitepos WordPress plugin. Versions prior to 3.6.0, and an earlier subset of versions prior to 3.5.0, are vulnerable. These plugin releases are integrated into WordPress‑based websites where the Outlet Manager role exists.

Risk and Exploitability

Once the user has the Outlet Manager role, the attacker can call the password‑reset API without further authorization, enabling them to reset any account password. The exploit requires no additional attacker privileges beyond that role, making it a low‑effort privilege escalation. The EPSS score is less than 1%, indicating a low but non‑zero probability of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. The CVSS score of 7.2 indicates high severity because it allows complete takeover of administrator accounts and any other site users’ credentials.

Generated by OpenCVE AI on August 13, 2026 at 08:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Vitepos WordPress plugin to version 3.6.0 or later, which implements the missing authorization check.
  • Verify that users assigned the Outlet Manager role no longer possess the ability to reset passwords, and adjust plugin settings or role capabilities accordingly.
  • Remove or downgrade the Outlet Manager role for users who do not require it, and enforce least privilege for all remaining roles.

Generated by OpenCVE AI on August 13, 2026 at 08:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-640

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Vitepos
Vitepos vitepos
Wordpress
Wordpress wordpress
Vendors & Products Vitepos
Vitepos vitepos
Wordpress
Wordpress wordpress

Mon, 10 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-640

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.
Title Vitepos < 3.6.0 - Outlet Manager+ Privilege Escalation
References

Subscriptions

Vitepos Vitepos
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-11T14:54:39.645Z

Reserved: 2026-06-30T13:05:39.752Z

Link: CVE-2026-14237

cve-icon Vulnrichment

Updated: 2026-08-11T14:53:45.640Z

cve-icon NVD

Status : Deferred

Published: 2026-08-10T07:16:46.937

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-14237

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:00:11Z

Weaknesses
  • CWE-269

    Improper Privilege Management