
Proof-of-concept exploit and lab for CVE-2026-81648, an unauthenticated arbitrary file deletion flaw in the WordPress CryptoPayment Gateway plugin.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected] · CVE-2026-81648
CryptoPayment Gateway 1.2.2 - Granwill
I am @abraxas_null. Loopback lab. The client is CVE-2026-81648-Abraxas-Labs.py.
The guard is never called. Direct POST vendor/cryptd/ajax.php, not admin-ajax.php. crpay_security_error sits unused. function=delete-file unlinks __DIR__/uploads/ plus folder plus file_name. Five .. from uploads reaches wp-content. No public patch in the tree I sat with. Same missing guard also covers settings overwrite and wallet recovery. The lab stops at a delete.
| CVE | CVE-2026-81648 · CVE.org |
| CWE | CWE-862 |
| CVSS | Critical: 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Product | WordPress - CryptoPayment Gateway |
| Affected | 1.2.1-1.2.2 |
| Patched | no public patch - disable the plugin |
| Auth | none |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only |
Unauthenticated POST JSON data.function=delete-file with a traversal file_name. Arbitrary file delete on the server. The same endpoint can overwrite gateway config and recover stored wallet credentials in cleartext. I am not printing a wallet recovery.
WPScan named a missing authorization check. I read ajax.php, then noticed crpay_security_error unused, then planted a lab index.php.
Witness, POST, witness. GET /wp-content/poc81648/index.php. POST data={"function":"delete-file",...}. GET again. The unique string must be gone.
Wrong turns: admin-ajax.php (this is not WordPress AJAX); GET (the switch reads POST JSON); function not inside data; too few ..; success JSON without the file disappearing; dumping get-settings / encryption; deleting wp-config.php.
Port 8088. CryptoPayment Gateway 1.2.2. wp-content/poc81648/index.php echoes POCWitness81648.
Target only 127.0.0.1:8088 (or the loopback you bound).
cd lab
docker compose up --force-recreate
python3 ../CVE-2026-81648-Abraxas-Labs.py
Witness: POCWitness81648 present before POST, absent after. JSON success without the delete is not it.
Ways to lose without learning anything:
POCWitness81648wp-config.phpThere is no public patch in 1.2.2. Disable CryptoPayment Gateway or block vendor/cryptd/ajax.php. Re-run CVE-2026-81648-Abraxas-Labs.py after you isolate it: the witness file must survive.
wpscan.com/vulnerability/9b1490a0-1381-4d22-8086-f75aade4e898/
wpscan.com/vulnerability/9b1490a0-1381-4d22-8086-f75aade4e898
Plugin directory: cryptopayment-gateway
Trac browser: plugins.trac.wordpress.org/cryptopayment-gateway
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
GNU Affero GPL v3.0. See LICENSE.
The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.