WordPress Plugin Vulnerabilities

Paytm Payment Gateway < 2.8.9 - Unauthenticated Order Status Manipulation via Payment Callback

Description

The plugin does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders, including marking unpaid orders as paid and reducing stock.

Proof of Concept

Affects Plugins

Fixed in 2.8.9

References

Classification

Miscellaneous

Original Researcher
Artus KG
Submitter
Artus KG
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-09-29 (about 2 days ago)
Added
2026-09-22 (about 9 days ago)
Last Updated
2026-09-28 (about 3 days ago)

Other