Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2026-81648 — Proof-of-concept exploit and lab for CVE-2026-81648, an unauthenticated arbitrary file deletion flaw in the WordPress CryptoPayment Gateway plugin. | Kitploit
उपकरण/GitHubGitHub/abraxas/cve-2026-81648
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationSecurity VirtualizationWeb SecurityPenetration TestingLabs & Practice
GitHubabraxas/cve-2026-81648

CVE-2026-81648

Proof-of-concept exploit and lab for CVE-2026-81648, an unauthenticated arbitrary file deletion flaw in the WordPress CryptoPayment Gateway plugin.

1810 दिन पहलेअभी तक समीक्षित नहीं
रिपॉजिटरी देखें

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

Abraxas Labs - CVE-2026-81648

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-81648

CVE-2026-81648

CryptoPayment Gateway 1.2.2 - Granwill

I am @abraxas_null. Loopback lab. The client is CVE-2026-81648-Abraxas-Labs.py.

The guard is never called. Direct POST vendor/cryptd/ajax.php, not admin-ajax.php. crpay_security_error sits unused. function=delete-file unlinks __DIR__/uploads/ plus folder plus file_name. Five .. from uploads reaches wp-content. No public patch in the tree I sat with. Same missing guard also covers settings overwrite and wallet recovery. The lab stops at a delete.

CVECVE-2026-81648 · CVE.org
CWECWE-862
CVSSCritical: 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
ProductWordPress - CryptoPayment Gateway
Affected1.2.1-1.2.2
Patchedno public patch - disable the plugin
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Unauthenticated POST JSON data.function=delete-file with a traversal file_name. Arbitrary file delete on the server. The same endpoint can overwrite gateway config and recover stored wallet credentials in cleartext. I am not printing a wallet recovery.


How I found it

WPScan named a missing authorization check. I read ajax.php, then noticed crpay_security_error unused, then planted a lab index.php.

Witness, POST, witness. GET /wp-content/poc81648/index.php. POST data={"function":"delete-file",...}. GET again. The unique string must be gone.

Wrong turns: admin-ajax.php (this is not WordPress AJAX); GET (the switch reads POST JSON); function not inside data; too few ..; success JSON without the file disappearing; dumping get-settings / encryption; deleting wp-config.php.


The lab

Port 8088. CryptoPayment Gateway 1.2.2. wp-content/poc81648/index.php echoes POCWitness81648.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-81648-Abraxas-Labs.py

Witness: POCWitness81648 present before POST, absent after. JSON success without the delete is not it.

Ways to lose without learning anything:

  • ajax JSON without the file disappearing
  • still serving POCWitness81648
  • deleting wp-config.php
  • dumping wallet keys
  • reverse shell

The fix

There is no public patch in 1.2.2. Disable CryptoPayment Gateway or block vendor/cryptd/ajax.php. Re-run CVE-2026-81648-Abraxas-Labs.py after you isolate it: the witness file must survive.


References

  • CVE-2026-81648 · NVD

  • CVE-2026-81648 · CVE.org

  • wpscan.com/vulnerability/9b1490a0-1381-4d22-8086-f75aade4e898/

  • github.com/advisories/GHSA-9r3q-6qw8-8pm7

  • nvd.nist.gov/vuln/detail/CVE-2026-81648

  • wpscan.com/vulnerability/9b1490a0-1381-4d22-8086-f75aade4e898

  • Plugin directory: cryptopayment-gateway

  • Trac browser: plugins.trac.wordpress.org/cryptopayment-gateway

  • SVN tags: plugins.svn.wordpress.org/cryptopayment-gateway

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

टूल डाउनलोड करें