Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x2ww-v6rp-cf3p

Опубликовано: 10 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.

The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.

EPSS

Процентиль: 17%
0.00257
Низкий

7.2 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.2
nvd
9 дней назад

The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's password, including an administrator's, and take over the account.

EPSS

Процентиль: 17%
0.00257
Низкий

7.2 High

CVSS3

Дефекты

CWE-269