Unrated severityNVD Advisory· Published Jul 30, 2026· Updated Jul 30, 2026
Persian Elementor (المنتور فارسی) <= 2.8.1 - Unauthenticated Price Manipulation via ZarinPal Widget
CVE-2026-1982
Description
The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured ZarinPal widget price. This makes it possible for unauthenticated attackers to submit arbitrary payment amounts to the ZarinPal gateway via the 'amount' parameter.
Affected products
1- Range: <=2.8.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.