OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-81809

HIGH · CVSS 7.5 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Paytm Payment Gateway plugin for WordPress versions prior to 2.8.9 is vulnerable to SQL injection due to improper data escaping from payment callbacks. This flaw allows unauthenticated users to manipulate SQL queries, potentially compromising the database integrity and exposing sensitive information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-81809
Severity
HIGH
CVSS
7.5
EPSS
0.18%
WordPress

Original NVD Description

The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection attacks.