← WordPress Vulnerabilities
WordPress security by component

Persian Elementor (المنتور فارسی)

Persian Elementor (المنتور فارسی) (persian-elementor) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 5.3.

Plugin slug: persian-elementor

CVE-2026-86809: Persian Elementor accepts payment authority from another transaction

Persian Elementor versions 2.7.10 through versions below 2.8.2 do not verify that the ZarinPal payment authority returned to the public callback belongs to the pending transaction being completed. An unauthenticated attacker can reuse a valid authority obtained from a different transaction to complete another pending order. The authoritative export does not identify the callback route, authority parameter, order parameter, or verification function.

PublishedSep 11, 2026
Known safe version2.8.2
Published vulnerabilities for persian-elementor
Safe version
Sep 11, 2026 CVE-2026-86809
Persian Elementor accepts payment authority from another transaction
Persian Elementor versions 2.7.10 through versions below 2.8.2 do not verify that the ZarinPal payment authority returned to the public callback belongs to the pending transaction being completed. An unauthenticated attacker can reuse a valid authority obtained from a different transaction to complete another pending order. The authoritative export does not identify the callback route, authority parameter, order parameter, or verification function.
2.8.2
CVE5.3
NVDPending
Jul 30, 2026 CVE-2026-1982
Persian Elementor ZarinPal widget accepts attacker-selected payment amounts
Persian Elementor through 2.8.1 trusts the unauthenticated amount request parameter when submitting a ZarinPal widget payment instead of validating it against the widget's configured price on the server. An anonymous attacker can therefore replace the intended amount with an arbitrary lower value and send that manipulated amount to the payment gateway. The official 2.8.2 changelog states that sensitive payment data is reread directly from the server, identifying 2.8.2 as the corrected release.
2.8.2
CVE5.3
NVDPending