PT-2026-104530 · WordPress · Tillkit

·

CVE-2026-91078

·

Published

2026-10-03

·

Updated

2026-10-04

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions TillKit WordPress plugin versions prior to 1.0.5
Description The plugin creates a privileged POS account upon activation that uses a hard-coded, publicly known PIN. The system does not require this PIN to be changed before use and authenticates the public POS login endpoint based solely on this PIN without performing identity or capability checks. This allows unauthenticated attackers to obtain a privileged POS session to read personal data of customers and site users, as well as modify store data.
Recommendations Update TillKit WordPress plugin to version 1.0.5 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91078

Affected Products

Tillkit