Review
TillKit
CVE published 2026-10-03
CVE-2026-91078
CVE-2026-91078 debrief based on CVE Program and NVD records. The TillKit WordPress plugin before 1.0.5 creates a privileged POS account with a hard-coded, publicly known PIN that does not require change before use. This allows unauthenticated attackers to obtain a privileged POS session, enabling them to read customer and site-user personal data and modify store data. Defenders of WordPress sites using th [truncated]