Medium severity5.3NVD Advisory· Published Sep 11, 2026· Updated Sep 11, 2026
CVE-2026-86809
CVE-2026-86809
Description
The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment authority obtained from a different transaction.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2>=2.7.10,<2.8.2+ 1 more
- (no CPE)range: >=2.7.10,<2.8.2
- (no CPE)range: <2.8.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.