CVE-2026-14237 PUBLISHED

Vitepos < 3.6.0 - Outlet Manager+ Privilege Escalation

Assigner: WPScan
Reserved: 30.06.2026 Published: 10.08.2026 Updated: 10.08.2026

The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.

Product Status

Vendor Unknown
Product vitepos
Versions Default: unaffected
  • affected from 3.4.0 to 3.6.0 (excl.)
Vendor Unknown
Product Vitepos
Versions Default: unaffected
  • affected from 0 to 3.5.0 (excl.)

Credits

  • Real_King_Engine (ISAL FRAMEWORK) finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE