Impact
The vulnerability is a classic CSRF flaw that allows an attacker to cause the victim to perform unwanted actions while authenticated. An attacker can trigger requests to the Erima Zarinpal Donate plugin that may change payment settings or initiate a transaction on behalf of the victim. The CVSS score of 4.3 indicates a moderate risk, meaning the flaw is not a high‑impact exploit but still can lead to financial loss if abused.
Affected Systems
The flaw affects the Erima Zarinpal Donate WordPress plugin with versions 1.0 and earlier. Users running any version of the plugin up to and including 1.0 are potentially vulnerable. The plugin is used to process Zarinpal payments within WordPress sites.
Risk and Exploitability
The EPSS score of less than 1% implies that a successful exploitation is considered unlikely. The flaw is not listed in the CISA KEV catalog. Based on the description, the attack vector would involve a malicious site or page that tricks an authenticated visitor into submitting a crafted request to the vulnerable plugin endpoint, which does not validate CSRF tokens before processing the action.
OpenCVE Enrichment
EUVD