rootpwn

high · CVSS v3 8.2 · EPSS 0.00136

CVE-2026-91078

The TillKit WordPress plugin before 1.0.5 creates a privileged POS account with a hard‑coded PIN that is never required to be changed. The p

Overview

The TillKit WordPress plugin before 1.0.5 creates a privileged POS account with a hard‑coded PIN that is never required to be changed. The public POS login endpoint authenticates solely on that PIN, allowing unauthenticated attackers to obtain a privileged session. This can expose customer data and allow modification of store data.

Description

The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal data and modify store data.

Impact

Confidentiality: attackers can read customer and site‑user personal data. Integrity: attackers can modify store data. Availability is not directly impacted. WordPress site owners, e‑commerce operators, and their customers are the primary stakeholders.

Remediation

1. Update the TillKit plugin to version 1.0.5 or later, which removes the hard‑coded PIN requirement. 2. If an update is not immediately possible, disable the public POS login endpoint or restrict it to trusted IP ranges. 3. Change the default PIN to a strong, unique value and enforce a password policy that requires a change on first use. 4. Monitor authentication logs for anomalous PIN usage and apply least‑privilege access controls to the POS account.

Risk context

The vulnerability has a high severity rating (CVSS v3 8.2) and a low EPSS score (0.00136), indicating a low probability of exploitation but a high potential impact if exploited. Defenders should treat this as a moderate‑to‑high priority issue and act promptly to mitigate exposure.

Affected products

  • TillKit WP plugin 1.0.0
  • TillKit WP plugin 1.0.1
  • TillKit WP plugin 1.0.2
  • TillKit WP plugin 1.0.3
  • TillKit WP plugin 1.0.4

Scores

Severity
high
CVSS v2
8.5
CVSS v3
8.2
CVSS v4
—
EPSS
0.00136

WordPress plugin POS authentication privilege_escalation data_exposure high_severity

← All CVEs