What is CVE-2026-14237?
CVE-2026-14237 is a critical authorization flaw in Vitepos WordPress plugin versions prior to 3.6.0. Due to a missing per-target authorization check in the point-of-sale password-reset API, the default 'Outlet Manager' role has overly broad privileges, allowing an attacker with this role to reset passwords of other users. Immediate update to the latest plugin version is recommended.
Azərbaycanca: CVE-2026-14237, Vitepos WordPress plaginin 3.6.0-dan əvvəlki versiyalarında aşkar edilmiş kritik icazə zəifliyidir. Satış nöqtəsi şifrə sıfırlama API-sində hədəfə görə icazə yoxlanışının aparılmaması səbəbindən, 'Outlet Manager' roluna malik istifadəçi icazə hüdudlarını aşaraq digər istifadəçilərin şifrələrini sıfırlaya bilir. Plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What privileges does an attacker need to exploit CVE-2026-14237?
The attacker needs to have the 'Outlet Manager' role. This role allows them to reset passwords of other users through the password-reset API that lacks a per-target authorization check.
Which versions of the Vitepos plugin are vulnerable to CVE-2026-14237?
All versions of the Vitepos plugin prior to 3.6.0 are vulnerable. Updating to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.