PatchSiren

vitepos CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review vitepos CVE published 2026-08-10

CVE-2026-14237

The CVE-2026-14237 vulnerability affects WordPress installations using the vitepos plugin before version 3.6.0 and Vitepos plugin before version 3.5.0. This vulnerability is classified as a privilege escalation issue due to insufficient authorization checks in the point-of-sale password-reset API. The custom Outlet Manager role is granted an overly broad password-reset capability by default, potentially a [truncated]