CVE-2026-81648
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing
CVSS
10.0
Critical
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 13, 2026 · Last modified: Sep 13, 2026
Not enough EPSS history yet.
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.
No related CVEs by CWE or product.