---
id: CVE-2026-81739
title: >-
  The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and
  escape data it stores from payment callbacks before outputting it in an admin
  page, and the integrity check on those callbacks can be forged when the
  gateway i…
summary: >-
  The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and
  escape data it stores from payment callbacks before outputting it in an admin
  page, and the integrity check on those callbacks can be forged when the
  gateway i…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
product: Paytm Payment Gateway
affected:
  - paytm_payment_gateway < 2.8.9
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T11:17:27.833'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81739'
references:
  - url: 'https://wpscan.com/vulnerability/f77f3f04-cb98-4687-9080-dd0c99a7e926/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-01T10:44:45.826864Z'
ingestedAt: '2026-10-01T06:38:44.650Z'
---

## Overview

The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts that will run in the session of a store administrator.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
