Description
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection attacks.
Published: 2026-10-01
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: SQL Injection leading to unauthorized data access or modification
Action: Patch Immediately
AI Analysis

Impact

The Paytm Payment Gateway WordPress plugin before version 2.8.9 does not properly escape data received from payment callbacks, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials. As a result, unauthenticated users can craft callback requests that inject arbitrary SQL statements into the database. A successful injection could allow read or write access to the site’s database, exposing transaction details or enabling manipulation of orders and financial records.

Affected Systems

WordPress sites that have the Paytm Payment Gateway plugin installed and are running a version older than 2.8.9. The plugin is listed as Unknown: Paytm Payment Gateway.

Risk and Exploitability

Exploitation requires no authentication and relies on the payment gateway being enabled without credentials. The attacker may send a crafted callback request from any network location to the plugin’s callback URL. The CVSS score of 7.5 indicates high severity. While an EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the lack of authentication combined with the ability to inject arbitrary SQL presents a high‑risk scenario. Attackers could corrupt or exfiltrate sensitive data once the injection is successful.

Generated by OpenCVE AI on October 1, 2026 at 14:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Paytm Payment Gateway to version 2.8.9 or later
  • If an upgrade cannot be applied immediately, disable the payment gateway or enforce valid credentials to prevent forged callbacks
  • Implement server‑side input validation or parameterized queries for all database interactions that use callback data. If possible, patch or custom modify the plugin to sanitize or escape callback inputs properly

Generated by OpenCVE AI on October 1, 2026 at 14:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Paytm
Paytm payment Gateway
Wordpress-extensions
Wordpress-extensions paytm Payment Gateway
Vendors & Products Paytm
Paytm payment Gateway
Wordpress-extensions
Wordpress-extensions paytm Payment Gateway

Thu, 01 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89

Thu, 01 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection attacks.
Title Paytm Payment Gateway < 2.8.9 - Unauthenticated SQLi via Payment Callback
References

Subscriptions

Paytm Payment Gateway
Wordpress-extensions Paytm Payment Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-01T10:45:49.737Z

Reserved: 2026-08-27T12:32:37.159Z

Link: CVE-2026-81809

cve-icon Vulnrichment

Updated: 2026-10-01T10:44:08.349Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T06:17:11.197

Modified: 2026-10-01T13:11:52.923

Link: CVE-2026-81809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:37:10Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')