Executive brief
The Persian Elementor plugin for WordPress, which provides localized features for the Elementor page builder, contains a security flaw in its payment processing component. This vulnerability allows unauthorized individuals to modify the price of items during the checkout process. As a result, attackers could potentially purchase goods or services for a price of their choosing, leading to financial loss and operational disruption for site owners.
Technical details
The Persian Elementor plugin for WordPress is vulnerable to price manipulation (CWE-472) in versions up to 2.8.1. The root cause is the ZarinPal widget trusting user-supplied input via the 'amount' parameter without performing server-side validation against the actual configured price. An unauthenticated remote attacker can exploit this by intercepting and modifying the payment request to submit an arbitrary amount to the ZarinPal gateway. This allows for the completion of transactions at unauthorized prices. A patch appears to be available in the plugin's changeset 3613858.
Affected products
- mohammadr3z Persian Elementor (المنتور فارسی) <= 2.8.1
Timeline
- 2026-07-30: disclosed
- 2026-07-30: advisory