Loading market data...
← Back to CVE feed

CVE-2026-81739

HIGH CVSS 7.5 View on NVD ↗

Description

The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts that will run in the session of a store administrator.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Published: Oct 01, 2026 06:17 UTC Modified: Oct 01, 2026 13:11 UTC