CVE-2026-14237: Vitepos < 3.6.0 - Outlet Manager+ Privilege Escalation
The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14237?
CVE-2026-14237 has a risk rating of 80, indicating a significant security concern.
How do I fix CVE-2026-14237?
To fix CVE-2026-14237, update the Vitepos WordPress plugin to version 3.6.0 or higher.
What is the impact of CVE-2026-14237?
CVE-2026-14237 allows an Outlet Manager to exploit the password-reset API, leading to potential privilege escalation.
Who is affected by CVE-2026-14237?
Any users of the Vitepos WordPress plugin prior to version 3.6.0 are affected by CVE-2026-14237.
What type of vulnerability is CVE-2026-14237?
CVE-2026-14237 is a privilege escalation vulnerability in the Vitepos WordPress plugin.