Skip to content
Critical Vulnerabilities in WordPress Plugins Expose Users to Attacks

Critical Vulnerabilities in WordPress Plugins Expose Users to Attacks

First seen 19 Sep 2026, 21:50 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 20, 2026 at 00:24 UTC
  • CVE-2026-81648 allows unauthorized admin actions in CryptoPayment Gateway.
  • CVE-2026-81294 enables privilege escalation via unverified OAuth2 emails in Authorizer.
  • No patch is available for CryptoPayment Gateway; users must disable the plugin.

Two critical vulnerabilities have been disclosed in popular WordPress plugins, affecting users of the CryptoPayment Gateway and Authorizer plugins. CVE-2026-81648 allows unauthenticated users to perform administrative actions, including file deletion and configuration overwrites, due to a lack of authorization checks in the CryptoPayment Gateway plugin (versions 1.2.1 to 1.2.2). Meanwhile, CVE-2026-81294 in the Authorizer plugin (all versions through 3.15.1) enables unauthenticated privilege escalation via unverified OAuth2 email addresses. Both vulnerabilities have been assigned critical CVSS scores, with CVE-2026-81648 rated at 10.0 and CVE-2026-81294 at 9.8. No patches are currently available for the CryptoPayment Gateway, while a patch for Authorizer has been released in version 3.15.2. Users are advised to disable the affected plugins or block access to vulnerable endpoints until fixes are implemented. The vulnerabilities were published on September 13 and September 2, 2026, respectively.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-02
CVE-2026-81294 published
Critical vulnerability in Authorizer plugin disclosed, affecting all versions through 3.15.1.
Sploitus
2026-09-13
CVE-2026-81648 published
Critical vulnerability in CryptoPayment Gateway plugin disclosed, allowing unauthorized admin actions.
Sploitus
2026-09-19
Current status of vulnerabilities
No patch available for CryptoPayment Gateway; patch for Authorizer released in version 3.15.2.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2026-81294 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed