WordPress Plugin Vulnerabilities

Vitepos < 3.6.0 - Outlet Manager+ Privilege Escalation

Description

The plugins do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.

Proof of Concept

Affects Plugins

Fixed in 3.6.0
Fixed in 3.5.0

References

Classification

Miscellaneous

Original Researcher
Real_King_Engine (ISAL FRAMEWORK)
Submitter
Real_King_Engine (ISAL FRAMEWORK)
Verified
Yes

Timeline

Publicly Published
2026-08-07 (about 3 days ago)
Added
2026-08-07 (about 2 days ago)
Last Updated
2026-08-07 (about 2 days ago)

Other