MinorCritical vulnerability
CVE-2026-81809 (CVSS 7.5)
NVD · officialPublished Oct 1, 2026Risk 23/100
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection attacks.
Technical details
CVSS
7.5
AV:NetworkAC:HighPR:NoneUI:NoneC:HighI:LowA:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source