VYPR

Zarinpal Gateway for WooCommerce

by WordPress

CVEs (1)

  • CVE-2026-2592HigFeb 17, 2026
    risk 0.43cvss 7.7epss 0.00

    The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Update in all versions up to and including 5.0.16. This is due to the payment callback handler 'Return_from_ZarinPal_Gateway' failing to validate that the…