S4E just found a medium-severity finding from http usage detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-45805 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in Paytm Payment Gateway plugin for WordPress affects v. through 2.7.3.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-45805
9.8
CVSShigh
Exploitable remotely over the internet · requires high privileges.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paytm Paytm Payment Gateway paytm-payments allows SQL Injection.This issue affects Paytm Payment Gateway: from n/a through 2.7.3.

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
Paytm Payment Gatewayby Paytm
n/a
payment_gatewayby paytm
0
Updated Aug 22, 2026View on NVD →
Detail

Paytm Payment Gateway plugin for WordPress is a popular e-commerce plugin that allows website owners to accept payments from their customers through the Paytm payment gateway. It is used for various purposes, including selling physical or digital products, subscriptions, donations, and bookings. The plugin offers a seamless payment experience, enabling users to pay using various payment methods, including credit/debit cards, net banking, UPI, and Paytm Wallet, among others.

However, the Paytm Payment Gateway plugin for WordPress has been found to have a critical vulnerability - CVE-2022-45805. This vulnerability allows attackers to inject malicious SQL commands into the plugin, allowing them to steal sensitive data, modify data, or escalate privileges. The vulnerability is caused due to improper neutralization of special elements used in SQL commands, allowing attackers to pass SQL statements as input to the backend database.

If this vulnerability is exploited, it can lead to severe consequences, including website compromise, theft of sensitive customer data such as passwords, credit card details, or personal information, website defacement, website downtime, and even loss of reputation and trust among customers.

In conclusion, it is essential to safeguard your website against vulnerabilities to protect sensitive data and avoid loss of reputation and trust. With the pro features of the s4e.io platform, users can quickly learn about vulnerabilities in their digital assets and take necessary precautions to protect their websites. So, ensure that your website is up-to-date, secure, and well-protected against cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners should take the following precautions:

  • Update the plugin to the latest available version
  • Implement strict input validation and sanitization
  • Configure the database to use secure authentication methods
  • Monitor database activity for suspicious SQL queries
  • Use a web application firewall to block SQL injection attacks

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.