CryptoPayment Gateway vulnerability

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.

Published 13 Sep 2026Updated 13 Sep 20261 sources
CVSS 10.0

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.