cleantalk
Vulnerabilities and Security Researches

Persian Elementor, CVE-2026-86809

CVE, Research URL

CVE-2026-86809

Application

Persian Elementor

Published on
Sep 11, 2026
Research Description
The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment authority obtained from a different transaction.
Affected versions
max 2.8.2.
Status
vulnerable