PT-2026-66351 · WordPress+1 · Persian-Elementor+1
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Persian Elementor (المنتور فارسی) versions prior to 2.8.2
Description
This issue involves price manipulation where the plugin trusts a user-supplied payment amount without server-side validation against the configured ZarinPal widget price. This allows unauthenticated attackers to submit arbitrary payment amounts to the ZarinPal gateway using the
amount parameter.Recommendations
Update the plugin to version 2.8.2 or later.
Avoid using the
amount parameter in the ZarinPal gateway integration until the update is applied.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Persian-Elementor
المنتور فارسی