← WordPress Vulnerabilities
WordPress security by component

Paytm Payment Gateway

Paytm Payment Gateway (paytm-payment-gateway) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Oct 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: paytm-payment-gateway

CVE-2026-81809: Paytm Payment Gateway: SQL injection

The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection attacks. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 2.8.9.

PublishedOct 01, 2026
Known safe version2.8.9
Published vulnerabilities for paytm-payment-gateway
Safe version
Oct 01, 2026 CVE-2026-81809
Paytm Payment Gateway: SQL injection
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection attacks. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 2.8.9.
2.8.9
CVEPending
NVDPending
Oct 01, 2026 CVE-2026-81739
Paytm Payment Gateway: Forged payment callbacks store administrator-facing XSS
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts that will run in the session of a store administrator. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 2.8.9.
2.8.9
CVEPending
NVDPending