The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any users password, including an administrators, and take over the account.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.