Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-1982 2 Mohammadr3z, Wordpress 2 المنتور فارسی, Wordpress 2026-07-30 5.3 Medium
The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured ZarinPal widget price. This makes it possible for unauthenticated attackers to submit arbitrary payment amounts to the ZarinPal gateway via the 'amount' parameter.