
PEACH
Un framework di isolamento del tenant
CVE-2026-81648 is a critical Missing Authorization vulnerability in the CryptoPayment Gateway WordPress plugin affecting versions 1.2.1 through 1.2.2. The flaw allows unauthenticated attackers to invoke administrative operations via an unguarded AJAX endpoint, including arbitrary file deletion, payment gateway configuration overwrite, and retrieval of stored wallet credentials in cleartext. It was publicly disclosed on September 10, 2026, and published to the NVD and GitHub Advisory Database on September 13, 2026. It carries a CVSS v3.1 base score of 10.0 (Critical) (WPScan, GitHub Advisory).
The root cause is CWE-862 (Missing Authorization): the plugin registers an AJAX endpoint that routes administrative actions without verifying whether the requesting user has appropriate privileges (also classified as CWE-284 / OWASP A5: Broken Access Control) (WPScan). Because WordPress AJAX endpoints are accessible to unauthenticated users by default unless explicitly restricted, any remote attacker can send crafted HTTP requests to this endpoint and trigger privileged operations. No authentication, session token, or nonce verification is required, making exploitation straightforward and automatable. The vulnerability was discovered and reported by researcher Pedro Pinho (WPScan). A proof-of-concept is scheduled for public release on October 1, 2026, to allow time for users to update (WPScan).
Successful exploitation allows an unauthenticated remote attacker to delete arbitrary files on the web server (potentially causing denial of service or enabling further attacks by removing security controls), overwrite payment gateway configuration (enabling payment redirection or fraud), and recover stored cryptocurrency wallet credentials in plaintext (leading to direct financial theft). The CVSS scope is marked as "Changed," indicating that the impact extends beyond the vulnerable plugin itself to the broader WordPress installation and underlying server. The combination of full confidentiality, integrity, and availability impact at the server level makes this a maximum-severity vulnerability with significant financial and operational consequences (GitHub Advisory, WPScan).
As of the disclosure date, no public proof-of-concept exploit code has been released, though WPScan has indicated a PoC will be published on October 1, 2026 (WPScan). There is no confirmed evidence of in-the-wild exploitation at this time, and the CVE is not listed in the CISA KEV catalog. The NVD SSVC assessment notes the vulnerability is automatable with total technical impact (GitHub Advisory). The EPSS score is approximately 0.277%, reflecting a currently low but non-negligible probability of exploitation within 30 days. No specific threat actor attribution has been reported.
readme.txt at /wp-content/plugins/cryptopayment-gateway/readme.txt)./wp-admin/admin-ajax.php with an action parameter corresponding to the plugin's registered hook.https://target.com/wp-admin/admin-ajax.php with the appropriate action parameter value corresponding to the plugin's unguarded AJAX router, without any authentication cookies or nonces..htaccess, or WordPress core files) to disable defenses or cause denial of service (WPScan, GitHub Advisory)./wp-admin/admin-ajax.php with action parameters associated with the CryptoPayment Gateway plugin from unexpected or external IP addresses; repeated requests in short succession suggesting automated scanning.admin-ajax.php without valid authentication cookies or nonces; HTTP 200 responses to these requests from unauthenticated sessions./wp-content/plugins/cryptopayment-gateway/).The WPScan advisory notes there is no known fix available in the plugin repository as of the disclosure date, and the affected plugin (cryptopayment-gateway) should be deactivated and removed until a patched version is released (WPScan). The GitHub Advisory references a patch but lists both affected and patched versions as "Unknown" (GitHub Advisory). Immediate recommended actions include: (1) deactivate and remove the plugin until a verified fix is available; (2) rotate all wallet credentials and payment gateway API keys that may have been exposed; (3) review server and WordPress access logs for signs of unauthorized AJAX requests; (4) restrict access to wp-admin/admin-ajax.php at the network or WAF level where feasible; and (5) monitor for unauthorized file deletions or configuration changes.
Wordfence included this vulnerability in its weekly WordPress vulnerability report for the period of September 7–13, 2026, highlighting it among notable disclosures (Wordfence). A Reddit thread in r/StopBadBots referenced this CVE in the context of a broader discussion about unpatched critical WordPress plugins (Reddit). Community reaction has focused on the severity of exposing cryptocurrency wallet credentials and the lack of an immediately available patch.
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."