Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

FluxContactConfidentialité© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2026-81648 — Proof-of-concept exploit and lab for CVE-2026-81648, an unauthenticated arbitrary file deletion flaw in the WordPress CryptoPayment Gateway plugin. | Kitploit
Outils/GitHubGitHub/abraxas/cve-2026-81648
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationSecurity VirtualizationWeb SecurityPenetration TestingLabs & Practice
GitHubabraxas/cve-2026-81648

CVE-2026-81648

Proof-of-concept exploit and lab for CVE-2026-81648, an unauthenticated arbitrary file deletion flaw in the WordPress CryptoPayment Gateway plugin.

18il y a 10 joursPas encore vérifié
Voir le dépôt

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

Abraxas Labs - CVE-2026-81648

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-81648

CVE-2026-81648

CryptoPayment Gateway 1.2.2 - Granwill

I am @abraxas_null. Loopback lab. The client is CVE-2026-81648-Abraxas-Labs.py.

The guard is never called. Direct POST vendor/cryptd/ajax.php, not admin-ajax.php. crpay_security_error sits unused. function=delete-file unlinks __DIR__/uploads/ plus folder plus file_name. Five .. from uploads reaches wp-content. No public patch in the tree I sat with. Same missing guard also covers settings overwrite and wallet recovery. The lab stops at a delete.

CVECVE-2026-81648 · CVE.org
CWECWE-862
CVSSCritical: 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
ProductWordPress - CryptoPayment Gateway
Affected1.2.1-1.2.2
Patchedno public patch - disable the plugin
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Unauthenticated POST JSON data.function=delete-file with a traversal file_name. Arbitrary file delete on the server. The same endpoint can overwrite gateway config and recover stored wallet credentials in cleartext. I am not printing a wallet recovery.


How I found it

WPScan named a missing authorization check. I read ajax.php, then noticed crpay_security_error unused, then planted a lab index.php.

Witness, POST, witness. GET /wp-content/poc81648/index.php. POST data={"function":"delete-file",...}. GET again. The unique string must be gone.

Wrong turns: admin-ajax.php (this is not WordPress AJAX); GET (the switch reads POST JSON); function not inside data; too few ..; success JSON without the file disappearing; dumping get-settings / encryption; deleting wp-config.php.


The lab

Port 8088. CryptoPayment Gateway 1.2.2. wp-content/poc81648/index.php echoes POCWitness81648.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-81648-Abraxas-Labs.py

Witness: POCWitness81648 present before POST, absent after. JSON success without the delete is not it.

Ways to lose without learning anything:

  • ajax JSON without the file disappearing
  • still serving POCWitness81648
  • deleting wp-config.php
  • dumping wallet keys
  • reverse shell

The fix

There is no public patch in 1.2.2. Disable CryptoPayment Gateway or block vendor/cryptd/ajax.php. Re-run CVE-2026-81648-Abraxas-Labs.py after you isolate it: the witness file must survive.


References

  • CVE-2026-81648 · NVD

  • CVE-2026-81648 · CVE.org

  • wpscan.com/vulnerability/9b1490a0-1381-4d22-8086-f75aade4e898/

  • github.com/advisories/GHSA-9r3q-6qw8-8pm7

  • nvd.nist.gov/vuln/detail/CVE-2026-81648

  • wpscan.com/vulnerability/9b1490a0-1381-4d22-8086-f75aade4e898

  • Plugin directory: cryptopayment-gateway

  • Trac browser: plugins.trac.wordpress.org/cryptopayment-gateway

  • SVN tags: plugins.svn.wordpress.org/cryptopayment-gateway

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Télécharger l’outil