Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-81648 — Proof-of-concept exploit and lab for CVE-2026-81648, an unauthenticated arbitrary file deletion flaw in the WordPress CryptoPayment Gateway plugin. | Kitploit
أدوات/GitHubGitHub/abraxas/cve-2026-81648
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationSecurity VirtualizationWeb SecurityPenetration TestingLabs & Practice
GitHubabraxas/cve-2026-81648

CVE-2026-81648

Proof-of-concept exploit and lab for CVE-2026-81648, an unauthenticated arbitrary file deletion flaw in the WordPress CryptoPayment Gateway plugin.

18منذ 10 أياملم تتم المراجعة بعد
عرض المستودع

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

Abraxas Labs - CVE-2026-81648

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-81648

CVE-2026-81648

CryptoPayment Gateway 1.2.2 - Granwill

I am @abraxas_null. Loopback lab. The client is CVE-2026-81648-Abraxas-Labs.py.

The guard is never called. Direct POST vendor/cryptd/ajax.php, not admin-ajax.php. crpay_security_error sits unused. function=delete-file unlinks __DIR__/uploads/ plus folder plus file_name. Five .. from uploads reaches wp-content. No public patch in the tree I sat with. Same missing guard also covers settings overwrite and wallet recovery. The lab stops at a delete.

CVECVE-2026-81648 · CVE.org
CWECWE-862
CVSSCritical: 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
ProductWordPress - CryptoPayment Gateway
Affected1.2.1-1.2.2
Patchedno public patch - disable the plugin
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Unauthenticated POST JSON data.function=delete-file with a traversal file_name. Arbitrary file delete on the server. The same endpoint can overwrite gateway config and recover stored wallet credentials in cleartext. I am not printing a wallet recovery.


How I found it

WPScan named a missing authorization check. I read ajax.php, then noticed crpay_security_error unused, then planted a lab index.php.

Witness, POST, witness. GET /wp-content/poc81648/index.php. POST data={"function":"delete-file",...}. GET again. The unique string must be gone.

Wrong turns: admin-ajax.php (this is not WordPress AJAX); GET (the switch reads POST JSON); function not inside data; too few ..; success JSON without the file disappearing; dumping get-settings / encryption; deleting wp-config.php.


The lab

Port 8088. CryptoPayment Gateway 1.2.2. wp-content/poc81648/index.php echoes POCWitness81648.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-81648-Abraxas-Labs.py

Witness: POCWitness81648 present before POST, absent after. JSON success without the delete is not it.

Ways to lose without learning anything:

  • ajax JSON without the file disappearing
  • still serving POCWitness81648
  • deleting wp-config.php
  • dumping wallet keys
  • reverse shell

The fix

There is no public patch in 1.2.2. Disable CryptoPayment Gateway or block vendor/cryptd/ajax.php. Re-run CVE-2026-81648-Abraxas-Labs.py after you isolate it: the witness file must survive.


References

  • CVE-2026-81648 · NVD

  • CVE-2026-81648 · CVE.org

  • wpscan.com/vulnerability/9b1490a0-1381-4d22-8086-f75aade4e898/

  • github.com/advisories/GHSA-9r3q-6qw8-8pm7

  • nvd.nist.gov/vuln/detail/CVE-2026-81648

  • wpscan.com/vulnerability/9b1490a0-1381-4d22-8086-f75aade4e898

  • Plugin directory: cryptopayment-gateway

  • Trac browser: plugins.trac.wordpress.org/cryptopayment-gateway

  • SVN tags: plugins.svn.wordpress.org/cryptopayment-gateway

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

تنزيل الأداة