OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-81739 (CVSS 7.5)

NVD · officialPublished Oct 1, 2026Risk 23/100

The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts that will run in the session of a store administrator.

CVSS
7.5
AV:NetworkAC:HighPR:NoneUI:RequiredC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source