Critical severity10.0NVD Advisory· Published Sep 13, 2026
CVE-2026-81648
CVE-2026-81648
Description
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 1.2.1 to 1.2.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.