CVE-2026-81740: CWE-287 Improper Authentication in Paytm Payment Gateway
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders, including marking unpaid orders as paid and reducing stock.
AI Analysis
Technical Summary
CVE-2026-81740 describes an improper authentication vulnerability (CWE-287) in the Paytm Payment Gateway WordPress plugin prior to version 2.8.9. The plugin does not validate payment callbacks when the secret key is not set, which is the default state immediately after activation. This flaw enables unauthenticated attackers to alter arbitrary order statuses, such as marking unpaid orders as paid and decreasing stock counts, potentially leading to financial and inventory inconsistencies.
Potential Impact
Attackers can exploit this vulnerability to fraudulently mark orders as paid without actual payment, causing financial loss and inventory mismanagement. The integrity of order processing is compromised, which can affect merchant revenue and customer trust.
Mitigation Recommendations
Upgrade the Paytm Payment Gateway WordPress plugin to version 2.8.9 or later, where this authentication issue has been addressed. Until the upgrade, ensure the secret key is properly configured immediately after plugin activation to prevent exploitation.
CVE-2026-81740: CWE-287 Improper Authentication in Paytm Payment Gateway
Description
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders, including marking unpaid orders as paid and reducing stock.
CVSS v3.1
Score 5.3medium
Affected software
Paytm Payment Gateway
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-81740 describes an improper authentication vulnerability (CWE-287) in the Paytm Payment Gateway WordPress plugin prior to version 2.8.9. The plugin does not validate payment callbacks when the secret key is not set, which is the default state immediately after activation. This flaw enables unauthenticated attackers to alter arbitrary order statuses, such as marking unpaid orders as paid and decreasing stock counts, potentially leading to financial and inventory inconsistencies.
Potential Impact
Attackers can exploit this vulnerability to fraudulently mark orders as paid without actual payment, causing financial loss and inventory mismanagement. The integrity of order processing is compromised, which can affect merchant revenue and customer trust.
Mitigation Recommendations
Upgrade the Paytm Payment Gateway WordPress plugin to version 2.8.9 or later, where this authentication issue has been addressed. Until the upgrade, ensure the secret key is properly configured immediately after plugin activation to prevent exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-08-27T11:47:22.935Z
- State
- PUBLISHED
Threat ID: 6abf4919a43b0b3b897a0eb8
Added to database: 10/02/2026, 06:03:05 UTC
Last enriched: 10/02/2026, 06:16:41 UTC
Last updated: 10/03/2026, 03:49:54 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.