Description
Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام &#8211; همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام &#8211; همگام سازی ووکامرس و باسلام: from n/a through <= 1.9.1.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a Cross‑Site Request Forgery vulnerability in the WordPress plugin hamsalam – همگام سازی ووکامرس و باسلام sync‑basalam. The plugin accepts requests without verifying the request origin, allowing an attacker to cause a victim’s authenticated browser to perform privileged actions such as changing plugin settings or triggering orders. This weakness is classified as CWE‑352, reflecting the absence of proper request intent validation.

Affected Systems

The vulnerability affects the hamsalam – همگام سازی ووکامرس و باسلام sync‑basalam WordPress plugin versions from the initial release through 1.9.1. No specific sub‑version breakpoints are listed, so all releases up to and including 1.9.1 are considered vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, but the EPSS score of less than 1% suggests that widespread exploitation is currently unlikely. The flaw is not listed in the CISA KEV catalog. The likely attack vector is remote; an attacker can craft a malicious link or hidden form that, when visited by a logged‑in user, sends a forged request to the site. Successful exploitation would allow the attacker to execute any operation that the victim’s credentials permit, potentially leading to data exposure or site compromise.

Generated by OpenCVE AI on August 1, 2026 at 10:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WordPress plugin to version 1.9.2 or later to remove the CSRF flaw
  • If an upgrade is not possible, disable the plugin or restrict execution of its endpoints to trusted users
  • Add a WordPress nonce or custom CSRF token to any forms or actions that invoke plugin functionality for an extra verification layer

Generated by OpenCVE AI on August 1, 2026 at 10:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Hamsalam
Hamsalam ووسلام &#8211; همگام سازی ووکامرس و باسلام
Wordpress
Wordpress wordpress
Vendors & Products Hamsalam
Hamsalam ووسلام &#8211; همگام سازی ووکامرس و باسلام
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام &#8211; همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام &#8211; همگام سازی ووکامرس و باسلام: from n/a through <= 1.9.1.
Title WordPress ووسلام – همگام سازی ووکامرس و باسلام plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N'}


Subscriptions

Hamsalam ووسلام &#8211; همگام سازی ووکامرس و باسلام
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:46:55.384Z

Reserved: 2026-07-13T06:13:44.978Z

Link: CVE-2026-61956

cve-icon Vulnrichment

Updated: 2026-07-13T13:46:50.709Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:30:04Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)