Vulnerability Description
The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-14237?
CVE-2026-14237 is a vulnerability with a CVSS score of 7.2 (HIGH). The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet ...
How severe is CVE-2026-14237?
CVE-2026-14237 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-14237?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.