Vulnerabilities and security researches forpersian-elementor persian-elementor
Direction: descendingSep 13, 2026
Persian Elementor # CVE-2026-86809
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 11, 2026
- Research Description
- The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment authority obtained from a different transaction.
- Affected versions
-
max 2.8.2.
- Status
-
vulnerable
Jul 31, 2026
Persian Elementor # CVE-2026-1982
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 30, 2026
- Research Description
- The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured ZarinPal widget price. This makes it possible for unauthenticated attackers to submit arbitrary payment amounts to the ZarinPal gateway via the 'amount' parameter.
- Affected versions
-
max 2.8.2.
- Status
-
vulnerable