Persian Elementor, CVE-2026-1982
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jul 30, 2026
- Research Description
- The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured ZarinPal widget price. This makes it possible for unauthenticated attackers to submit arbitrary payment amounts to the ZarinPal gateway via the 'amount' parameter.
- Affected versions
-
max 2.8.2.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| Persian Elementor (CVE-2026-1982) , Jul 31, 2026 |
| Persian Elementor (CVE-2026-86809) , Sep 13, 2026 |