Review
vitepos
CVE published 2026-08-10
CVE-2026-14237
The CVE-2026-14237 vulnerability affects WordPress installations using the vitepos plugin before version 3.6.0 and Vitepos plugin before version 3.5.0. This vulnerability is classified as a privilege escalation issue due to insufficient authorization checks in the point-of-sale password-reset API. The custom Outlet Manager role is granted an overly broad password-reset capability by default, potentially a [truncated]