๐Ÿ” CVE Alert

CVE-2026-8157

HIGH 8.8

Vitepos < 3.4.2 - Outlet Manager+ Privilege Escalation

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator.

Vendor unknown
Product vitepos
Published Jun 22, 2026
Last Updated Jun 22, 2026
Stay Ahead of the Next One

Get instant alerts for unknown vitepos

Be the first to know when new high vulnerabilities affecting unknown vitepos are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Vitepos
0 < 3.4.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/6680cc6a-9758-4040-bb39-7b9545041dc3/

Credits

Real_King_Engine (ISAL FRAMEWORK) WPScan