CyberRota Analysis
AI-GeneratedThe Paytm Payment Gateway plugin for WordPress prior to version 2.8.9 is vulnerable due to inadequate sanitization and escaping of data from payment callbacks, which can be exploited by unauthenticated users to inject malicious scripts. This flaw poses a significant risk as it allows attackers to execute scripts in the session of an administrator, potentially leading to unauthorized access or data manipulation. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this high-severity vulnerability.
Original NVD Description
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts that will run in the session of a store administrator.