Description
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.
Published: 2026-09-13
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized file deletion & credential exposure
Action: Immediate Patch
AI Analysis

Impact

A missing authorization check on one of CryptoPayment Gateway’s AJAX endpoints allows any user to perform privileged actions without authentication, a weakness identified as CWE‑862. The flaw permits unauthenticated site visitors to delete arbitrary files on the server, overwrite the payment gateway configuration, and retrieve stored wallet credentials in cleartext. These capabilities threaten confidentiality by exposing payment data, compromise integrity by enabling destructive changes to site files and configuration, and introduce availability risks through potential site defacement or shutdown.

Affected Systems

WordPress sites that have1.2.2 are affected. The plugin is vendor‑owned but no official CNA vendor identification is available; the vulnerability does not extend to other plugins or core WordPress components.

Risk and Exploitability

The attack vector is unauthenticated remote access via a simple HTTP request to the plugin’s AJAX URL, which requires no credentials. The vulnerability scores a CVSS of 10, indicating maximum severity, while the EPSS score of less than 1% indicates a low probability of exploitation at present. The issue is not listed in the CISA KEV catalog. Once exploited, an attacker can delete or replace site files, alter payment gateway settings, and capture wallet credentials, potentially leading to complete website compromise and financial loss.

Generated by OpenCVE AI on September 15, 2026 at 17:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CryptoPayment Gateway to the latest patched release that enforces proper authorization checks on all AJAX endpoints.
  • If an upgrade is not immediately possible, block access to the vulnerable AJAX action by configuring a web application firewall or server‑level URL filtering to prevent unauthenticated requests.
  • Monitor the WordPress file system and database for unexpected deletions, configuration changes, or newly exposed wallet credentials and investigate any anomalies promptly.

Generated by OpenCVE AI on September 15, 2026 at 17:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-732
CWE-862
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-732

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.
Title CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-14T12:39:42.962Z

Reserved: 2026-08-27T09:27:21.125Z

Link: CVE-2026-81648

cve-icon Vulnrichment

Updated: 2026-09-14T12:36:55.396Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T21:17:01.930

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-81648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:15:14Z

Weaknesses