Description
The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal data and modify store data.
Published: 2026-10-03
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated privilege escalation to POS
Action: Immediate Patch
AI Analysis

Impact

The TillKit WordPress plugin creates a privileged point‑of‑sale account with a hard‑coded, publicly known PIN during installation and fails to require the PIN be changed before use. The public POS login endpoint authenticates a user solely on that PIN, with no additional identity or capability verification. As a result, an attacker can simply send a request containing the known PIN to establish a privileged POS session and then read customer data, view site‑user personal information, and modify store inventory or transactions. This flaw enables complete control over the POS system without any credential or permissions checks.

Affected Systems

All installations of the TillKit WordPress plugin with a version earlier than 1.0.5 are affected. The plugin is distributed under an unknown vendor identity but is deployed on WordPress sites where the POS functionality is required.

Risk and Exploitability

The vulnerability offers a remote, unauthenticated attack vector that requires only knowledge of a hard‑coded PIN. Although no EPSS score is available and the flaw is not listed in CISA KEV, the lack of authentication and the potential to compromise sensitive data and store operations indicate a high exploitation risk. An attacker can trigger the vulnerable endpoint with a simple HTTP request, making exploitation extremely low effort and easily automated.

Generated by OpenCVE AI on October 3, 2026 at 07:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the TillKit WordPress plugin to version 1.0.5 or newer, which implements proper PIN change requirements and additional authentication checks.
  • If an upgrade cannot be performed immediately, manually change the default PIN stored in the database, then disable the public POS login endpoint or restrict it to a trusted network segment.
  • Apply network‑level restrictions or firewall rules to limit access to the POS endpoint only to authorized personnel or systems, and enable logging of all POS authentication attempts for monitoring and forensic purposes.

Generated by OpenCVE AI on October 3, 2026 at 07:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-798

Sat, 03 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal data and modify store data.
Title TillKit < 1.0.5 - Unauthenticated POS Takeover via Hard-Coded Default Manager PIN
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-03T15:12:21.432Z

Reserved: 2026-09-14T17:26:53.255Z

Link: CVE-2026-91078

cve-icon Vulnrichment

Updated: 2026-10-03T15:00:46.571Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:45.507

Modified: 2026-10-03T16:16:41.237

Link: CVE-2026-91078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T07:30:20Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-798

    Use of Hard-coded Credentials