๐Ÿ” CVE Alert

CVE-2026-86809

MEDIUM 5.3

Persian Elementor < 2.8.2 - Unauthenticated ZarinPal Payment Callback Authority Bypass

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment authority obtained from a different transaction.

Vendor unknown
Product persian elementor
Published Sep 11, 2026
Last Updated Sep 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown persian elementor

Be the first to know when new medium vulnerabilities affecting unknown persian elementor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / Persian Elementor
2.7.10 < 2.8.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/ed1f8ac4-078b-49c6-b7c5-7d422a20e59e/

Credits

Artus KG WPScan