CVE-2026-81648
Received
Published: 13 Sept 2026, 20:06
Last modified:13 Sept 2026, 20:06
Vulnerability Summary
Overall Risk (default)
critical
90/100 CVSS Score
10 CRITICAL
v3.1 (cve.org)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected
Timeline
13 Sept 2026, 20:06
Published
Vulnerability first disclosed
Description
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.
CVSS Metrics
- v3.1•CRITICAL•Score: 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Systems
- unknown•cryptopayment gateway
≥ 1.2.1, ≤ 1.2.2