Description
The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.
Published: 2026-08-10
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Vitepos WordPress plugin versions before 3.6.0 do not perform a per‑target authorization check in their point‑of‑sale password‑reset API. This flaw grants users with the custom Outlet Manager role an overly broad capability to reset any user’s password, including that of site administrators. Consequently, an attacker who can become an Outlet Manager can take control of any account, compromising the confidentiality, integrity, and availability of the entire site.

Affected Systems

The affected product is the Vitepos WordPress plugin. Versions prior to 3.6.0, and an earlier subset of versions prior to 3.5.0, are vulnerable. These plugin releases are integrated into WordPress‑based websites where the Outlet Manager role exists.

Risk and Exploitability

Once the user has the Outlet Manager role, the attacker can call the password‑reset API without further authorization, enabling them to reset any account password. The exploit requires no additional attacker privileges beyond that role, making it a low‑effort privilege escalation. No exploit probability is available from EPSS, and the vulnerability is not currently listed in the CISA KEV catalog. The severity of the flaw is high because it allows complete takeover of administrator accounts and any other site users’ credentials.

Generated by OpenCVE AI on August 10, 2026 at 07:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Vitepos WordPress plugin to version 3.6.0 or later, which implements the missing authorization check.
  • Verify that users assigned the Outlet Manager role no longer possess the ability to reset passwords, and adjust plugin settings or role capabilities accordingly.
  • Remove or downgrade the Outlet Manager role for users who do not require it, and enforce least privilege for all remaining roles.

Generated by OpenCVE AI on August 10, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-640

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.
Title Vitepos < 3.6.0 - Outlet Manager+ Privilege Escalation
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-10T06:00:18.586Z

Reserved: 2026-06-30T13:05:39.752Z

Link: CVE-2026-14237

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T07:30:14Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password