CVE-2026-91078
Received Received - Intake

TillKit WordPress Plugin Hard-Coded PIN Authentication Bypass

Vulnerability report for CVE-2026-91078, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: WPScan

Description

The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal data and modify store data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tillkit tillkit to 1.0.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The TillKit WordPress plugin before version 1.0.5 creates a privileged Point of Sale (POS) account during activation but does not require changing the default PIN. The plugin's public POS login endpoint only uses this hard-coded PIN for authentication without additional checks, allowing unauthenticated attackers to gain privileged access.

Detection Guidance

Check the installed version of the TillKit WordPress plugin. If it is below 1.0.5, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files for version information.

Impact Analysis

Unauthenticated attackers can exploit this to access privileged POS sessions, read customer and site-user personal data, and modify store data. This could lead to data breaches, financial loss, or unauthorized changes to store operations.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to personal data. GDPR requires protecting personal data, and HIPAA mandates safeguarding protected health information. A breach could result in legal penalties and reputational damage.

Mitigation Strategies

Update the TillKit plugin to version 1.0.5 or later immediately. If updating is not possible, consider disabling the plugin until an update is applied to prevent unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91078. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart