THREAT OPS › Threat News › [NVD] CVE-2026-81648 (CRITICAL 10.0) — The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway
[NVD] CVE-2026-81648 (CRITICAL 10.0) — The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway
CVE-2026-81648 CVSS: 10.0 CRITICAL Published: 2026-09-13T21:17:01.930
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet crede
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-81648cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81648