Impact
An unauthenticated cross‑site request forgery flaw in the WordPress Zarinpal Gateway plugin allows any remote actor to spur the plugin into processing payment requests without the knowledge or consent of the site visitor. The weakness, classified as CWE‑352, means that crafted requests can trigger payment actions or modify transaction data, potentially leading to fraudulent charges or unauthorized fund movements.
Affected Systems
The WordPress Zarinpal Gateway Plugin, all releases up to and including version 5.1.0, running on any WordPress site that loads the plugin.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑to‑moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that exploitation would most likely occur via a crafted link or form that a victim visits, which would invoke the plugin’s payment processing functionality under the victim’s browser context.
OpenCVE Enrichment