CVSS
7.2
CVSS v3.1
EPSS
0.3%
Exploit Prediction Score
Published
August 10, 2026
Exploitability
EPSS probability 0.3%
The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).