SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-1982

MEDIUM · CVSS 5.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Persian Elementor plugin for WordPress is vulnerable to price manipulation due to a lack of server-side validation of user-supplied payment amounts, allowing unauthenticated attackers to exploit this weakness and submit arbitrary payment values to the ZarinPal payment gateway. This vulnerability affects all versions up to and including 2.8.1, posing a risk of financial fraud. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-1982
Severity
MEDIUM
CVSS
5.3
EPSS
0.20%
WordPress

Original NVD Description

The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured ZarinPal widget price. This makes it possible for unauthenticated attackers to submit arbitrary payment amounts to the ZarinPal gateway via the 'amount' parameter.