Impact
The Paytm Payment Gateway WordPress plugin before version 2.8.9 does not properly escape data received from payment callbacks, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials. As a result, unauthenticated users can craft callback requests that inject arbitrary SQL statements into the database. A successful injection could allow read or write access to the site’s database, exposing transaction details or enabling manipulation of orders and financial records.
Affected Systems
WordPress sites that have the Paytm Payment Gateway plugin installed and are running a version older than 2.8.9. The plugin is listed as Unknown: Paytm Payment Gateway.
Risk and Exploitability
Exploitation requires no authentication and relies on the payment gateway being enabled without credentials. The attacker may send a crafted callback request from any network location to the plugin’s callback URL. The CVSS score of 7.5 indicates high severity. While an EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the lack of authentication combined with the ability to inject arbitrary SQL presents a high‑risk scenario. Attackers could corrupt or exfiltrate sensitive data once the injection is successful.
OpenCVE Enrichment