rootpwn

high · CVSS v3 7.5

CVE-2026-81740

The Paytm Payment Gateway WordPress plugin before 2.8.9 fails to verify payment callbacks when the secret key is not configured, allowing at

Overview

The Paytm Payment Gateway WordPress plugin before 2.8.9 fails to verify payment callbacks when the secret key is not configured, allowing attackers to spoof callbacks. This can lead to unauthorized order status changes and inventory manipulation. It affects sites using the plugin immediately after activation.

Description

The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders, including marking unpaid orders as paid and reducing stock.

Impact

Confidentiality: attackers can alter order data; Integrity: unauthorized order status changes; Availability: potential stock depletion. Defenders: WordPress site owners, e-commerce managers, payment gateway administrators.

Remediation

Update the plugin to version 2.8.9 or later. Ensure the secret key is configured before activation. Verify that callback verification is enabled. Monitor order logs for suspicious status changes.

Risk context

High severity (CVSS 7.5). Immediate attention recommended; no EPSS data available.

Affected products

  • Paytm Payment Gateway WP plugin

Scores

Severity
high
CVSS v2
5
CVSS v3
7.5
CVSS v4
—
EPSS
—

wordpress payment-gateway callback unauthenticated order-manipulation plugin-vulnerability high-severity

← All CVEs