Description
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders, including marking unpaid orders as paid and reducing stock.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Order Status Manipulation
Action: Immediate Patch
AI Analysis

Impact

The Paytm Payment Gateway WordPress plugin prior to version 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation. As a result, an attacker can send a crafted HTTP request to the plugin’s callback URL and alter the status of any order, including marking unpaid orders as paid or reducing inventory stock. This flaw undermines the integrity of sales data and can lead to financial loss and inventory discrepancies. The weakness corresponds to CWE-287, Improper Authentication.

Affected Systems

WordPress sites that have installed the Paytm Payment Gateway plugin version earlier9 are affected. The issue exists regardless of other configuration settings because the secret key defaults to an empty value on activation, and the plugin performs no authentication for callback requests until a secret key is configured.

Risk and Exploitability

EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 5.3 indicates moderate overall risk. Based on the description, it is inferred that an attacker can exploit the flaw by issuing an unauthenticated HTTP request to the plugin’s publicly accessible callback endpoint. The lack of authentication lowers the barrier to exploitation and increases the likelihood that the vulnerability could be used to manipulate order states and generate fraudulent revenue unless mitigated.

Generated by OpenCVE AI on October 2, 2026 at 14:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Paytm Payment Gateway 2.8.9 or later to apply the fix that requires callback authentication with a secret key.
  • Configure a secret key in the plugin settings; any non-empty value will enforce authentication before state changes are applied.
  • Restrict the payment callback URL to accept traffic only from known Paytm IP addresses or block unauthenticated requests using a firewall rule.

Generated by OpenCVE AI on October 2, 2026 at 14:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Paytm
Paytm payment Gateway
Wordpress-extensions
Wordpress-extensions paytm Payment Gateway
Vendors & Products Paytm
Paytm payment Gateway
Wordpress-extensions
Wordpress-extensions paytm Payment Gateway

Fri, 02 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders, including marking unpaid orders as paid and reducing stock.
Title Paytm Payment Gateway < 2.8.9 - Unauthenticated Order Status Manipulation via Payment Callback
References

Subscriptions

Paytm Payment Gateway
Wordpress-extensions Paytm Payment Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-02T10:54:12.472Z

Reserved: 2026-08-27T11:47:22.935Z

Link: CVE-2026-81740

cve-icon Vulnrichment

Updated: 2026-10-02T10:46:00.648Z

cve-icon NVD

Status : Received

Published: 2026-10-02T06:16:41.450

Modified: 2026-10-02T11:17:35.053

Link: CVE-2026-81740

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:46:48Z

Weaknesses