PatchSiren

TillKit CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review TillKit CVE published 2026-10-03

CVE-2026-91078

CVE-2026-91078 debrief based on CVE Program and NVD records. The TillKit WordPress plugin before 1.0.5 creates a privileged POS account with a hard-coded, publicly known PIN that does not require change before use. This allows unauthenticated attackers to obtain a privileged POS session, enabling them to read customer and site-user personal data and modify store data. Defenders of WordPress sites using th [truncated]