Impact
The TillKit WordPress plugin creates a privileged point‑of‑sale account with a hard‑coded, publicly known PIN during installation and fails to require the PIN be changed before use. The public POS login endpoint authenticates a user solely on that PIN, with no additional identity or capability verification. As a result, an attacker can simply send a request containing the known PIN to establish a privileged POS session and then read customer data, view site‑user personal information, and modify store inventory or transactions. This flaw enables complete control over the POS system without any credential or permissions checks.
Affected Systems
All installations of the TillKit WordPress plugin with a version earlier than 1.0.5 are affected. The plugin is distributed under an unknown vendor identity but is deployed on WordPress sites where the POS functionality is required.
Risk and Exploitability
The vulnerability offers a remote, unauthenticated attack vector that requires only knowledge of a hard‑coded PIN. Although no EPSS score is available and the flaw is not listed in CISA KEV, the lack of authentication and the potential to compromise sensitive data and store operations indicate a high exploitation risk. An attacker can trigger the vulnerable endpoint with a simple HTTP request, making exploitation extremely low effort and easily automated.
OpenCVE Enrichment