The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-13 21:17
Updated : 2026-09-14 21:10
NVD link : CVE-2026-81648
Mitre link : CVE-2026-81648
CVE.ORG link : CVE-2026-81648
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
