CRITICAL
10 CVE-2026-81648 Published 13 Sept 2026
WordPress CryptoPayment Gateway File Deletion Vulnerability
Worried this affects one of your servers?
The CryptoPayment Gateway WordPress plugin, versions 1.2.1 to 1.2.2, has a critical security flaw.
Unauthenticated users can exploit an unprotected AJAX endpoint to perform administrative operations, such as:
- Deleting arbitrary files on the server
- Overwriting the payment gateway configuration
- Recovering stored wallet credentials in cleartext
Reference: CVE-2026-81648 on NVD
← Back to Security News