Sploitus Critical Vulnerabilities in WordPress Plugins Expose Users to Attacks
Article Content
- •CVE-2026-81648 allows unauthorized admin actions in CryptoPayment Gateway.
- •CVE-2026-81294 enables privilege escalation via unverified OAuth2 emails in Authorizer.
- •No patch is available for CryptoPayment Gateway; users must disable the plugin.
Two critical vulnerabilities have been disclosed in popular WordPress plugins, affecting users of the CryptoPayment Gateway and Authorizer plugins. CVE-2026-81648 allows unauthenticated users to perform administrative actions, including file deletion and configuration overwrites, due to a lack of authorization checks in the CryptoPayment Gateway plugin (versions 1.2.1 to 1.2.2). Meanwhile, CVE-2026-81294 in the Authorizer plugin (all versions through 3.15.1) enables unauthenticated privilege escalation via unverified OAuth2 email addresses. Both vulnerabilities have been assigned critical CVSS scores, with CVE-2026-81648 rated at 10.0 and CVE-2026-81294 at 9.8. No patches are currently available for the CryptoPayment Gateway, while a patch for Authorizer has been released in version 3.15.2. Users are advised to disable the affected plugins or block access to vulnerable endpoints until fixes are implemented. The vulnerabilities were published on September 13 and September 2, 2026, respectively.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-81294 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…