CVE-2026-91078: TillKit WordPress Plugin Vulnerability Exposes Sensitive Data
The TillKit WordPress plugin before version 1.0.5 has a critical vulnerability that allows unauthenticated attackers to gain a privileged POS session, leading to potential data breaches and unauthorized modifications. This vulnerability has a CVSS score of 8.2, indicating high severity. The flaw stems from the plugin's use of a hard-coded, publicly known PIN for the POS account without requiring a change before use.