Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 30 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mohammadr3z
Mohammadr3z المنتور فارسی Wordpress Wordpress wordpress |
|
| Vendors & Products |
Mohammadr3z
Mohammadr3z المنتور فارسی Wordpress Wordpress wordpress |
Thu, 30 Jul 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured ZarinPal widget price. This makes it possible for unauthenticated attackers to submit arbitrary payment amounts to the ZarinPal gateway via the 'amount' parameter. | |
| Title | Persian Elementor (المنتور فارسی) <= 2.8.1 - Unauthenticated Price Manipulation via ZarinPal Widget | |
| Weaknesses | CWE-472 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-07-30T15:51:47.194Z
Reserved: 2026-02-05T14:44:02.400Z
Link: CVE-2026-1982
Updated: 2026-07-30T15:51:43.033Z
Status : Deferred
Published: 2026-07-30T03:16:24.647
Modified: 2026-07-30T16:17:10.337
Link: CVE-2026-1982
No data.
OpenCVE Enrichment
Updated: 2026-08-03T11:30:03Z