CyberRota Analysis
AI-GeneratedThe CryptoPayment Gateway plugin for WordPress versions 1.2.1 to 1.2.2 is critically vulnerable due to a lack of authorization checks on an AJAX endpoint, enabling unauthenticated users to perform administrative actions. This vulnerability can lead to severe impacts, including unauthorized file deletions, configuration overwrites, and exposure of sensitive wallet credentials in cleartext. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.
Original NVD Description
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.