๐Ÿ” CVE Alert

CVE-2026-14237

UNKNOWN 0.0

Vitepos < 3.6.0 - Outlet Manager+ Privilege Escalation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.

Vendor unknown
Product vitepos
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for unknown vitepos

Be the first to know when new unknown vulnerabilities affecting unknown vitepos are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / vitepos
3.4.0 < 3.6.0
Unknown / Vitepos
0 < 3.5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/7f1eb6ec-c4fb-4c0d-887d-1812a84e29c0/

Credits

Real_King_Engine (ISAL FRAMEWORK) WPScan