WordPress Plugin Vulnerabilities

Paytm Payment Gateway < 2.8.9 - Unauthenticated Stored XSS via Payment Callback

Description

The plugin does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts that will run in the session of a store administrator.

Proof of Concept

Affects Plugins

Fixed in 2.8.9

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Artus KG
Submitter
Artus KG
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-09-29 (about 2 days ago)
Added
2026-09-29 (about 1 day ago)
Last Updated
2026-09-30 (about 8 hours ago)

Other