Executive brief
CryptoPayment Gateway is a WordPress plugin that integrates cryptocurrency payment processing into WordPress sites. An authorization flaw in its AJAX endpoints allows unauthenticated attackers to delete files, modify payment configurations, and extract wallet credentials, compromising both the site's integrity and customer payment data.
Technical details
The plugin fails to enforce authorization checks on one or more AJAX endpoints, allowing unauthenticated users to invoke administrative operations. The vulnerability enables arbitrary file deletion, payment gateway configuration tampering, and cleartext recovery of stored wallet credentials. Attack is network-accessible and requires no authentication or user interaction. CVSS score of 10.0 reflects the severity of administrative action exposure without access controls. No patch information is currently available.
Affected products
- CryptoPayment Gateway CryptoPayment Gateway 1.2.1 to 1.2.2
Timeline
- 2026-09-10: disclosed
- 2026-09-13: advisory