PT-2026-104530 · WordPress · Tillkit
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
TillKit WordPress plugin versions prior to 1.0.5
Description
The plugin creates a privileged POS account upon activation that uses a hard-coded, publicly known PIN. The system does not require this PIN to be changed before use and authenticates the public POS login endpoint based solely on this PIN without performing identity or capability checks. This allows unauthenticated attackers to obtain a privileged POS session to read personal data of customers and site users, as well as modify store data.
Recommendations
Update TillKit WordPress plugin to version 1.0.5 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tillkit