CVE-2026-86809: Unknown Persian Elementor
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment authority obtained from a different transaction.
Affected products
- Unknown Persian Elementor: from 2.7.10, before 2.8.2 (fixed in 2.8.2)
Published 2026-09-11. Last modified 2026-09-11.