Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-86809

MEDIUM NVD
CVSS Score 5.3
Severity MEDIUM
Published Sep 11, 2026
Vendor unknown

Description

The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment authority obtained from a different transaction.

References