WordPress security by component
Persian Elementor (المنتور فارسی)
Persian Elementor (المنتور فارسی) (persian-elementor) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 5.3.
Plugin slug:
persian-elementorLatest vulnerability
CVE-2026-86809: Persian Elementor accepts payment authority from another transaction
Persian Elementor versions 2.7.10 through versions below 2.8.2 do not verify that the ZarinPal payment authority returned to the public callback belongs to the pending transaction being completed. An unauthenticated attacker can reuse a valid authority obtained from a different transaction to complete another pending order. The authoritative export does not identify the callback route, authority parameter, order parameter, or verification function.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-86809
Persian Elementor accepts payment authority from another transaction
Persian Elementor versions 2.7.10 through versions below 2.8.2 do not verify that the ZarinPal payment authority returned to the public callback belongs to the pending transaction being completed. An unauthenticated attacker can reuse a valid authority obtained from a different transaction to complete another pending order. The authoritative export does not identify the callback route, authority parameter, order parameter, or verification function.
|
2.8.2 |
CVE5.3
NVDPending
|
| Jul 30, 2026 |
CVE-2026-1982
Persian Elementor ZarinPal widget accepts attacker-selected payment amounts
Persian Elementor through 2.8.1 trusts the unauthenticated amount request parameter when submitting a ZarinPal widget payment instead of validating it against the widget's configured price on the server. An anonymous attacker can therefore replace the intended amount with an arbitrary lower value and send that manipulated amount to the payment gateway. The official 2.8.2 changelog states that sensitive payment data is reread directly from the server, identifying 2.8.2 as the corrected release.
|
2.8.2 |
CVE5.3
NVDPending
|