The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal data and modify store data.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 03 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal data and modify store data.
Title TillKit < 1.0.5 - Unauthenticated POS Takeover via Hard-Coded Default Manager PIN
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-03T06:00:27.173Z

Reserved: 2026-09-14T17:26:53.255Z

Link: CVE-2026-91078

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:45.507

Modified: 2026-10-03T06:16:45.507

Link: CVE-2026-91078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.