Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-81648: CryptoPayment Gateway plugin lets anyone delete files and steal data

CVE-2026-81648 · published 13 days ago
Summary

The CryptoPayment Gateway plugin for WordPress (versions 1.2.1 and 1.2.2) does not verify who is calling a specific background request. Because of this, anyone on the internet can tell the site to remove files, change payment settings, or view saved wallet passwords in plain text. Update to a patched version or remove the plugin until the vendor releases a fix, and review your server for any unwanted changes.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
unknown cryptopayment gateway <= 1.2.2
Original advisory text
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations...
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.
Severity
10.0 Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-862Missing Authorization
Timeline
Published13 Sep 2026
Updated27 Sep 2026
First seen13 Sep 2026
Sources
CVE-2026-81648 · MITRE
Track software like this
Free during beta