WordPress security by component
Paytm Payment Gateway
Paytm Payment Gateway (paytm-payment-gateway) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Oct 01, 2026; an upstream CVSS base score is still pending.
Plugin slug:
paytm-payment-gatewayLatest vulnerability
CVE-2026-81809: Paytm Payment Gateway: SQL injection
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection attacks. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 2.8.9.
| Safe version |
|
||
|---|---|---|---|
| Oct 01, 2026 |
CVE-2026-81809
Paytm Payment Gateway: SQL injection
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection attacks. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 2.8.9.
|
2.8.9 |
CVEPending
NVDPending
|
| Oct 01, 2026 |
CVE-2026-81739
Paytm Payment Gateway: Forged payment callbacks store administrator-facing XSS
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts that will run in the session of a store administrator. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 2.8.9.
|
2.8.9 |
CVEPending
NVDPending
|