MinorCritical vulnerability
CVE-2026-81739 (CVSS 7.5)
NVD · officialPublished Oct 1, 2026Risk 23/100
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts that will run in the session of a store administrator.
Technical details
CVSS
7.5
AV:NetworkAC:HighPR:NoneUI:RequiredC:HighI:HighA:High
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source