CRITICAL 10 CVE-2026-81648 Published 13 Sept 2026

WordPress CryptoPayment Gateway File Deletion Vulnerability

Worried this affects one of your servers?

The CryptoPayment Gateway WordPress plugin, versions 1.2.1 to 1.2.2, has a critical security flaw.

Unauthenticated users can exploit an unprotected AJAX endpoint to perform administrative operations, such as:

  • Deleting arbitrary files on the server
  • Overwriting the payment gateway configuration
  • Recovering stored wallet credentials in cleartext

Reference: CVE-2026-81648 on NVD

← Back to Security News