---
id: CVE-2026-81648
title: >-
  The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply
  an authorization check on one of its AJAX endpoints, allowing unauthenticated
  users to invoke administrative operations, including deleting arbitrary files
  on …
summary: >-
  The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply
  an authorization check on one of its AJAX endpoints, allowing unauthenticated
  users to invoke administrative operations, including deleting arbitrary files
  on …
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-862
product: CryptoPayment Gateway
affected:
  - cryptopayment_gateway >= 1.2.1 <= 1.2.2
published: '2026-09-13'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T21:10:17.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81648'
references:
  - url: 'https://wpscan.com/vulnerability/9b1490a0-1381-4d22-8086-f75aade4e898/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-14T12:37:13.841082Z'
ingestedAt: '2026-09-14T15:23:07.431Z'
epss: 0.00498
epssPercentile: 0.4014
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/abraxas/CVE-2026-81648'
  checkedAt: '2026-09-26T09:06:01.795Z'
exploitAvailable: true
---

## Overview

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
