CVE-2026-1982
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Summary
The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured ZarinPal widget price. This makes it possible for unauthenticated attackers to submit arbitrary payment amounts to the ZarinPal gateway via the 'amount' parameter.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mohammadr3z | المنتور فارسی | 0 <= 2.8.1 | affected |
Weaknesses
- CWE-472: CWE-472 External Control of Assumed-Immutable Web Parameter
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/da675a50-c7ac-4859-9795-4b0f1dc56c7b?source=cve
- https://plugins.trac.wordpress.org/changeset/3613858/persian-elementor
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.