Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-81648

CryptoPayment Gateway WordPress Plugin Admin Auth Bypass

CryptoPayment Gateway WordPress plugin (1.2.1-1.2.2) skips an AJAX authorization check, allowing unauthenticated admin access to sites running the affected versions. CVSS 10.0.

cat cve-2026-81648.json
Vendor
CryptoPayment Gateway
Product
CryptoPayment Gateway WordPress Plugin (versions 1.2.1 to 1.2.2)
CVSS
10.0
EPSS (exploit probability)
N/A
Status
unpatched
Published

The CryptoPayment Gateway WordPress plugin in versions 1.2.1 and 1.2.2 fails to check authorization on an AJAX handler, allowing any unauthenticated visitor to invoke functions the plugin reserves for administrators. The vulnerable endpoint is reachable via WordPress’s admin-ajax.php dispatcher without any role or capability verification.

Consult the WPScan advisory for confirmed patch status and the fixed version. Until a patch is applied, deactivating the plugin is the practical mitigation. Payment processor API credentials and transaction logs associated with the affected installation should be audited for unauthorized access.