Impact
The Paytm Payment Gateway WordPress plugin prior to version 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation. As a result, an attacker can send a crafted HTTP request to the plugin’s callback URL and alter the status of any order, including marking unpaid orders as paid or reducing inventory stock. This flaw undermines the integrity of sales data and can lead to financial loss and inventory discrepancies. The weakness corresponds to CWE-287, Improper Authentication.
Affected Systems
WordPress sites that have installed the Paytm Payment Gateway plugin version earlier9 are affected. The issue exists regardless of other configuration settings because the secret key defaults to an empty value on activation, and the plugin performs no authentication for callback requests until a secret key is configured.
Risk and Exploitability
EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 5.3 indicates moderate overall risk. Based on the description, it is inferred that an attacker can exploit the flaw by issuing an unauthenticated HTTP request to the plugin’s publicly accessible callback endpoint. The lack of authentication lowers the barrier to exploitation and increases the likelihood that the vulnerability could be used to manipulate order states and generate fraudulent revenue unless mitigated.
OpenCVE Enrichment