CVE-2026-14237
Received Received - Intake

Unauthorized Password Reset in Vitepos WordPress Plugin

Vulnerability report for CVE-2026-14237, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: WPScan

Description

The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vitepos WordPress plugin before 3.6.0 and Vitepos Lite before 3.5.0 have a flaw where the Outlet Manager role can reset any user's password, including administrators, due to missing authorization checks in the password-reset API. This allows privilege escalation and account takeover.

Detection Guidance

Check the installed version of the Vitepos WordPress plugin. If it is below 3.6.0 (or 3.5.0 for Lite), the system is vulnerable. Use WordPress admin panel or run a command like 'wp plugin list' if using WP-CLI to verify versions.

Impact Analysis

An attacker with the Outlet Manager role could reset administrator passwords, gain full control of the WordPress site, and potentially steal sensitive data or disrupt operations.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or health data, violating GDPR and HIPAA requirements for data protection and access controls.

Mitigation Strategies

Update the Vitepos plugin to version 3.6.0 or later (3.5.0 for Lite). Remove or restrict the custom Outlet Manager role if not needed. Review user accounts for unauthorized changes after updating.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14237. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart