{"id":"CVE-2026-86809","title":"The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to comple…","summary":"The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to comple…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-345"],"product":"Persian Elementor","affected":["persian_elementor >= 2.7.10 < 2.8.2"],"published":"2026-09-11","updated":"2026-09-11","sourceUpdated":"2026-09-11T17:35:21.440","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86809","references":[{"url":"https://wpscan.com/vulnerability/ed1f8ac4-078b-49c6-b7c5-7d422a20e59e/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-11T12:05:46.682514Z"},"ingestedAt":"2026-09-11T16:45:47.922Z","epss":0.00114,"epssPercentile":0.01716,"slug":"CVE-2026-86809","body":"## Overview\n\nThe Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment authority obtained from a different transaction.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}