CVE-2026-91078 - TillKit < 1.0.5 - Unauthenticated POS Takeover via Hard-Coded Default Manager PIN
CVE ID :CVE-2026-91078 Published : Oct. 3, 2026, 6:16 a.m. | 11 hours, 8 minutes ago Description :The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates...