CVE-2026-81809: Paytm Payment Gateway < 2.8.9 - Unauthenticated SQLi via Payment Callback
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Paytm Payment Gateway WordPress pluginto a version that resolves this vulnerability.Fixed in 2.8.9
Event History
Frequently Asked Questions
Which deployments are exposed to unauthenticated exploitation?
Sites using a Paytm Payment Gateway plugin version earlier than 2.8.9 are exposed when the gateway is enabled without credentials. In that configuration, an attacker can forge the payment callback integrity check.
Does an attacker need an account or valid payment credentials?
No. The issue is described as unauthenticated, and the callback integrity check can be forged when the gateway is enabled without credentials.
What should be checked to determine whether a site is affected?
Check whether the installed Paytm Payment Gateway WordPress plugin version is earlier than 2.8.9, and whether its gateway is enabled without credentials. Both conditions are relevant to the described unauthenticated attack path.