OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-81809 (CVSS 7.5)

NVD · officialPublished Oct 1, 2026Risk 23/100

The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection attacks.

CVSS
7.5
AV:NetworkAC:HighPR:NoneUI:NoneC:HighI:LowA:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source