Impact
The Paytm Payment Donation plugin for WordPress contains a reflected XSS vulnerability (CWE‑79). Improper sanitization of user input in the plugin’s web page generation allows an attacker to inject arbitrary JavaScript that is executed in the victim’s browser when the constructed URL or form is loaded. Exploitation can result in cookie theft, session hijacking, defacement, or phishing.
Affected Systems
Affected instances include WordPress sites that have installed integrationdevpaytm Paytm Payment Donation plugin version 2.3.1 or earlier. No specific WordPress version requirement is noted, so any site running the vulnerable plugin is at risk.
Risk and Exploitability
The CVSS score of 7.1 denotes a moderate to high risk, while the EPSS score of <1% indicates a low but non‑zero probability of exploitation, and the flaw is not listed in CISA’s KEV catalog. Attackers can activate the XSS via a crafted URL or a maliciously constructed form input that is reflected by the plugin. If the site does not enforce additional sanitization or a strict Content‑Security‑Policy, the injected script can run with the privileges of the visiting user.
OpenCVE Enrichment
EUVD