Impact
A missing authorization check on one of CryptoPayment Gateway’s AJAX endpoints allows any user to perform privileged actions without authentication, a weakness identified as CWE‑862. The flaw permits unauthenticated site visitors to delete arbitrary files on the server, overwrite the payment gateway configuration, and retrieve stored wallet credentials in cleartext. These capabilities threaten confidentiality by exposing payment data, compromise integrity by enabling destructive changes to site files and configuration, and introduce availability risks through potential site defacement or shutdown.
Affected Systems
WordPress sites that have1.2.2 are affected. The plugin is vendor‑owned but no official CNA vendor identification is available; the vulnerability does not extend to other plugins or core WordPress components.
Risk and Exploitability
The attack vector is unauthenticated remote access via a simple HTTP request to the plugin’s AJAX URL, which requires no credentials. The vulnerability scores a CVSS of 10, indicating maximum severity, while the EPSS score of less than 1% indicates a low probability of exploitation at present. The issue is not listed in the CISA KEV catalog. Once exploited, an attacker can delete or replace site files, alter payment gateway settings, and capture wallet credentials, potentially leading to complete website compromise and financial loss.
OpenCVE Enrichment