CVE-2022-45362 HIGH

CVE-2022-45362: WordPress Paytm Payment Gateway Plugin <= 2.7.0 is vulnerable to Server Side Request Forgery (SSRF)

Vendor Paytm
Product Paytm Payment Gateway
Weakness CWE-918 · SSRF
Published December 7, 2023
Last update April 28, 2026

CVSS base score

7.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

Server-Side Request Forgery (SSRF) vulnerability in Paytm Paytm Payment Gateway.This issue affects Paytm Payment Gateway: from n/a through 2.7.0.

Explanation of Vulnerability in Simple Terms

02Summary

The Paytm Payment Gateway up to version 2.7.0 contains a server-side request forgery vulnerability that allows an attacker to make the payment gateway send requests to internal or external systems on the attacker's behalf. No authentication is required. The vulnerability can leak sensitive information and modify data on systems the gateway can reach, though availability is not affected.

What an attacker can do

03Attacker Capabilities

Make the payment gateway send requests to internal systems and read or modify data accessible from those systems.

Potential impact on your site

04Site Impact

Attackers can access internal systems, steal data, or modify records if the gateway can reach them—without needing valid credentials.

Conditions required to exploit

05Prerequisites

Network access to the vulnerable payment gateway; no authentication or user interaction required.

Key dates

06Disclosure timeline

December 7, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE