CVE-2026-8157Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-22: 2Patch / Workaround · 2026-06-22: 1Technical Details · 2026-06-22: 206-22
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • ADK Cyber@ADKCyber
    Patch

    WordPress sites using Vitepos before 3.4.2 should update to fix privilege escalation via the REST API (CVE-2026-8157). Review affected installations. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/fjJxXlGFj8

    Post summary

    The tweet urges WordPress sites running Vitepos <3.4.2 to update because of a high‑severity privilege escalation vulnerability (CVE‑2026‑8157) affecting the REST API.

    0000054
    93 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8157 Privilege Escalation in Vitepos WordPress Plugin Before 3.4.2 via ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8157 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces a new Privilege Escalation vulnerability (CVE-2026-8157) affecting Vitepos WordPress Plugin versions before 3.4.2, without providing PoC, exploit code, or patch details.

    00000112
    4.1K followersView on X

Explore more