CVE-2026-86809: Persian Elementor < 2.8.2 - Unauthenticated ZarinPal Payment Callback Authority Bypass
The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment authority obtained from a different transaction.
Affected Software
Event History
Frequently Asked Questions
Which plugin versions are affected?
Persian Elementor versions 2.7.10 through versions earlier than 2.8.2 are affected.
What does an attacker need to exploit this issue?
An attacker does not need authentication or user interaction, but needs a valid ZarinPal payment authority obtained from a different transaction. They can use it to complete a pending order whose authority is not verified against that transaction.
Are payment workflows using ZarinPal exposed?
The affected callback is the ZarinPal payment callback. Sites using the affected plugin versions and processing pending orders through that callback are exposed.