SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81648

CRITICAL · CVSS 10 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The CryptoPayment Gateway plugin for WordPress versions 1.2.1 to 1.2.2 is critically vulnerable due to a lack of authorization checks on an AJAX endpoint, enabling unauthenticated users to perform administrative actions. This vulnerability can lead to severe impacts, including unauthorized file deletions, configuration overwrites, and exposure of sensitive wallet credentials in cleartext. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-81648
Severity
CRITICAL
CVSS
10
EPSS
0.28%
WordPress

Original NVD Description

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.