OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-81739

HIGH · CVSS 7.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Paytm Payment Gateway plugin for WordPress prior to version 2.8.9 is vulnerable due to inadequate sanitization and escaping of data from payment callbacks, which can be exploited by unauthenticated users to inject malicious scripts. This flaw poses a significant risk as it allows attackers to execute scripts in the session of an administrator, potentially leading to unauthorized access or data manipulation. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this high-severity vulnerability.

CVE
CVE-2026-81739
Severity
HIGH
CVSS
7.5
EPSS
0.22%
WordPress

Original NVD Description

The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts that will run in the session of a store administrator.