CyberRota Analysis
AI-GeneratedThe Paytm Payment Gateway plugin for WordPress versions prior to 2.8.9 is vulnerable to SQL injection due to improper data escaping from payment callbacks. This flaw allows unauthenticated users to manipulate SQL queries, potentially compromising the database integrity and exposing sensitive information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.
Original NVD Description
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection attacks.