---
id: CVE-2026-86809
title: >-
  The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not
  verify that the payment authority returned to its ZarinPal payment callback
  belongs to the transaction being completed, allowing unauthenticated attackers
  to comple…
summary: >-
  The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not
  verify that the payment authority returned to its ZarinPal payment callback
  belongs to the transaction being completed, allowing unauthenticated attackers
  to comple…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-345
product: Persian Elementor
affected:
  - persian_elementor >= 2.7.10 < 2.8.2
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T17:35:21.440'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86809'
references:
  - url: 'https://wpscan.com/vulnerability/ed1f8ac4-078b-49c6-b7c5-7d422a20e59e/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-11T12:05:46.682514Z'
ingestedAt: '2026-09-11T16:45:47.922Z'
epss: 0.00114
epssPercentile: 0.01719
---

## Overview

The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment authority obtained from a different transaction.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
