TillKit < 1.0.5 - Unauthenticated POS Takeover via Hard-Coded Default Manager PIN
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.2epss 0.2%
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal data and modify store data.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Affected products
Unknown · TillKitpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/7ab037d6-c670-4eaf-be0d-11cc9e20b18e/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.