CVE-2026-81648 is a missing-authorization vulnerability affecting CryptoPayment Gateway for WordPress versions 1.2.1 through 1.2.2. An AJAX endpoint fails to enforce an authorization check before performing administrative operations. A remote unauthenticated attacker can invoke the endpoint to delete arbitrary server files, overwrite payment-gateway configuration, and recover wallet credentials stored by the plugin in cleartext.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This seven-file disclosure and local reproduction repository contains one Python exploit proof, documentation, an AGPLv3 license, and Docker Compose files for a loopback-only WordPress/MySQL lab. CVE-2026-81648-Abraxas-Labs.py is a standalone Python script, not a Metasploit/Nuclei module. It connects only to 127.0.0.1:8088 and targets CryptoPayment Gateway's direct vendor AJAX handler rather than WordPress admin-ajax.php. The script first checks for a marker in a controlled witness page, submits a URL-encoded data parameter specifying function=delete-file and a traversal path, then re-fetches the page and treats disappearance of POCWitness81648 as successful deletion. The Compose configuration uses WordPress 6.4 with PHP 8.2 and MySQL 8.0, publishes only 127.0.0.1:8088, and expects a locally supplied cryptopayment-gateway plugin tree mounted read-only. Although the README describes the broader reported impact as unauthorized administrative operations, configuration overwrite, and wallet-credential recovery, the included executable code does not extract credentials, create persistence, or execute commands; it only demonstrates destructive file deletion against a prearranged lab file.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An improper authorization vulnerability in CryptoPayment Gateway WordPress plugin versions 1.2.1 through 1.2.2. An unauthenticated attacker can invoke administrative AJAX operations to delete arbitrary server files, overwrite payment-gateway configuration, and recover stored wallet credentials in cleartext.
A critical unauthenticated authorization-bypass vulnerability in CryptoPayment Gateway WordPress plugin versions 1.2.1 through 1.2.2. It permits unauthenticated administrative actions through an AJAX endpoint, including arbitrary file deletion, payment-gateway configuration overwrite, and recovery of stored wallet credentials in cleartext.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.