Description
The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment authority obtained from a different transaction.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Payment Completion
Action: Apply Patch
AI Analysis

Impact

The Persian Elementor WordPress plugin versions 2.7.10 through the release before 2.8.2 contains a flaw that allows an unauthenticated attacker to finish a pending order by submitting a ZarinPal payment authority that belongs to a different transaction. The plugin does not verify that the callback authority returned to the payment endpoint matches the transaction being finalized, resulting in an unauthorized payment completion. This weakness is a decrease in due diligence for payment authority verification (CWE-345), enabling financial loss for the site owner.

Affected Systems

The vulnerability affects installations of the Persian Elementor WordPress plugin earlier than version 2.8.2. Any WordPress site deploying that plugin is at risk until the plugin is updated or removed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending a crafted HTTP callback request to the plugin’s payment verification endpoint, without needing any prior authentication. Since the plugin accepts a valid authority received from another transaction, the attacker can force a transaction to settle, potentially draining site funds.

Generated by OpenCVE AI on September 11, 2026 at 16:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Persian Elementor to version 2.8.2 or later.
  • If the plugin is unnecessary, disable or uninstall it entirely.
  • Set up monitoring or alerting for unexpected or unauthorized payment completions.

Generated by OpenCVE AI on September 11, 2026 at 16:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Fri, 11 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Fri, 11 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-345
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment authority obtained from a different transaction.
Title Persian Elementor < 2.8.2 - Unauthenticated ZarinPal Payment Callback Authority Bypass
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-11T12:06:50.953Z

Reserved: 2026-09-08T13:30:57.624Z

Link: CVE-2026-86809

cve-icon Vulnrichment

Updated: 2026-09-11T12:05:29.571Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T11:16:57.150

Modified: 2026-09-11T17:35:21.440

Link: CVE-2026-86809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:15:05Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity