Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 03 Oct 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-798 |
Sat, 03 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sat, 03 Oct 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 CWE-798 |
Sat, 03 Oct 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal data and modify store data. | |
| Title | TillKit < 1.0.5 - Unauthenticated POS Takeover via Hard-Coded Default Manager PIN | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-03T15:12:21.432Z
Reserved: 2026-09-14T17:26:53.255Z
Link: CVE-2026-91078
Updated: 2026-10-03T15:00:46.571Z
Status : Received
Published: 2026-10-03T06:16:45.507
Modified: 2026-10-03T16:16:41.237
Link: CVE-2026-91078
No data.
OpenCVE Enrichment
Updated: 2026-10-03T17:00:13Z
-
CWE-287
Improper Authentication