Impact
The Persian Elementor WordPress plugin versions 2.7.10 through the release before 2.8.2 contains a flaw that allows an unauthenticated attacker to finish a pending order by submitting a ZarinPal payment authority that belongs to a different transaction. The plugin does not verify that the callback authority returned to the payment endpoint matches the transaction being finalized, resulting in an unauthorized payment completion. This weakness is a decrease in due diligence for payment authority verification (CWE-345), enabling financial loss for the site owner.
Affected Systems
The vulnerability affects installations of the Persian Elementor WordPress plugin earlier than version 2.8.2. Any WordPress site deploying that plugin is at risk until the plugin is updated or removed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending a crafted HTTP callback request to the plugin’s payment verification endpoint, without needing any prior authentication. Since the plugin accepts a valid authority received from another transaction, the attacker can force a transaction to settle, potentially draining site funds.
OpenCVE Enrichment