CVE-2026-96815: WordPress Vitepos plugin <= 3.5.0 - Privilege Escalation vulnerability
Published Sep 30, 2026
·Updated
Custom role Privilege Escalation in Vitepos <= 3.5.0 versions.
Affected Software
1 affected component
WordPress Vitepos plugin<=3.5.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Vitepos Pluginto a version that resolves this vulnerability.Fixed in 3.5.1
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires high privileges (PR:H). It is not described as exploitable by unauthenticated or low-privileged users.
2
Can this be exploited remotely without user interaction?
Yes. The vector is network-accessible (AV:N), requires low attack complexity (AC:L), and does not require user interaction (UI:N).
3
What security impact could successful exploitation have?
Successful exploitation can have high impact on confidentiality, integrity, and availability. The issue is categorized as privilege escalation involving custom roles.
4
Which versions are identified as affected?
Vitepos versions 3.5.0 and earlier are identified as affected by the available data.