Sceawere

Vulnerability Detail

CVE-2026-91078UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TillKit Insecure Authentication Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
13h ago
Vendor
Unknown
Product
TillKit
Attack Type
CWE-287 Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal data and modify store data.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-10-03T06:16:45.507Z",
  "pubdate": "2026-10-03T06:16:45.507Z",
  "executiveSummary": "The TillKit WordPress plugin (prior to version 1.0.5) contains a critical authentication vulnerability arising from the implementation of a hard-coded, publicly known PIN for a default privileged POS account created upon activation. This flaw allows unauthenticated remote attackers to bypass standard WordPress access controls by leveraging the known PIN to gain a privileged session.\nThe vulnerability type is categorized as Improper Authentication. The impact is severe, as successful exploitation grants the attacker full access to the privileged POS interface. This unauthorized access enables the exfiltration of sensitive customer information and site-user personal data, as well as the unauthorized modification of store data, such as transactions or inventory records. The flaw affects all installations of the TillKit plugin version 1.0.4 and earlier. Risk implications are extreme, as no identity or capability checks are performed at the POS login endpoint, requiring only the static, hard-coded PIN to establish a session. Attackers do not need valid WordPress administrative credentials or user accounts to perform the exploit, as the endpoint is exposed to the public network.",
  "technicalDetails": "The root cause of this vulnerability lies in the plugin's architectural design regarding session establishment and credential management. Upon activation, the TillKit plugin automatically provisions a privileged POS account within its internal logic. This account is initialized with a hard-coded PIN that is publicly accessible to anyone analyzing the plugin's source code or documentation. The plugin's public POS login endpoint serves as the primary authentication gatekeeper; however, the implementation of this endpoint is fundamentally insecure.\nSpecifically, the authentication logic fails to perform any secondary identity verification or capability checks. Instead, it relies exclusively on the provided PIN. Because this PIN is identical across all installations of the affected plugin versions and is not enforced to be changed upon initial deployment, the mechanism essentially functions as an open bypass for any remote actor aware of the hard-coded credential.\nThe attack flow proceeds as follows: First, an unauthenticated attacker identifies the POS login endpoint exposed by the plugin on the public internet. Second, the attacker submits the known hard-coded PIN to the endpoint. Third, because the backend logic lacks comprehensive validation protocols—specifically, it does not check for user-level permissions or unique session tokens tied to authorized administrative users—the application accepts the static PIN as a valid authentication factor. Finally, the server issues a privileged POS session to the attacker. This session provides an interface with elevated privileges, allowing the attacker to interact with the POS functionality as if they were an authorized operator.\nPost-exploitation impact includes full unauthorized access to the POS backend. An attacker can perform read operations to exfiltrate sensitive customer PII (Personally Identifiable Information) and site-user data, or perform write operations to modify store data, potentially resulting in financial loss or data integrity compromise. The vulnerability is exploitable remotely over HTTP/HTTPS protocols without requiring any pre-existing session or authentication context. The lack of rate-limiting or credential-rotation enforcement exacerbates the risk, allowing automated brute-force attempts unnecessary, given the predictability of the static PIN."
}
CVE-2026-91078: TillKit Insecure Authentication Vulnerability (HIGH Severity, CVSS: 8.2) | Sceawere