Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-81739

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Oct 01, 2026
Vendor unknown

Description

The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts that will run in the session of a store administrator.

References