🔐 CVE Alert

CVE-2026-1982

MEDIUM 5.3

Persian Elementor (المنتور فارسی) <= 2.8.1 - Unauthenticated Price Manipulation via ZarinPal Widget

CVSS Score
5.3
EPSS Score
0.2%
EPSS Percentile
10th

The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured ZarinPal widget price. This makes it possible for unauthenticated attackers to submit arbitrary payment amounts to the ZarinPal gateway via the 'amount' parameter.

CWE CWE-472
Vendor mohammadr3z
Product المنتور فارسی
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for mohammadr3z المنتور فارسی

Be the first to know when new medium vulnerabilities affecting mohammadr3z المنتور فارسی are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

mohammadr3z / المنتور فارسی
0 ≤ 2.8.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/da675a50-c7ac-4859-9795-4b0f1dc56c7b?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3613858/persian-elementor

Credits

Chiao-Lin Yu (Steven Meow)