Pardakht Delkhah < 2.9.3 - Unauthenticated Stored XSS
Description
Unauthenticated stored XSS in پلاگین پرداخت دلخواه WordPress plugin before 2.9.3 allows attackers to inject arbitrary scripts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated stored XSS in پلاگین پرداخت دلخواه WordPress plugin before 2.9.3 allows attackers to inject arbitrary scripts.
Vulnerability
The پلاگین پرداخت دلخواه (Pardakht Delkhah) WordPress plugin versions before 2.9.3 fail to sanitize and escape some parameters [1]. This allows an unauthenticated attacker to inject malicious JavaScript payloads through HTTP requests. The injected payloads are stored and later executed when a user with high privileges, such as an administrator, visits a page from the plugin.
Exploitation
An unauthenticated attacker can send a crafted request containing an XSS payload in a vulnerable parameter [1]. No authentication or special network position is required. The payload is stored by the plugin without sanitization. When a high-privilege user (e.g., an admin) subsequently visits any plugin page where the payload is rendered, the script executes in their browser session.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser. This can lead to session hijacking, credential theft, or forced administrative actions. The attack achieves stored cross-site scripting (XSS) with an impact on confidentiality, integrity, and availability, particularly affecting privileged users.
Mitigation
Update the پلاگین پرداخت دلخواه plugin to version 2.9.3 or later, which fixes the vulnerability [1]. No workaround is available. The plugin is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog at the time of publication.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- WordPress/پلاگین پرداخت دلخواهdescription
- Range: <2.9.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/4000ba69-d73f-4c5b-a299-82898304cebbmitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.