Unrated severityNVD Advisory· Published Oct 2, 2026
CVE-2026-81740
CVE-2026-81740
Description
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders, including marking unpaid orders as paid and reducing stock.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.8.9
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.