Junglewise Threat Intelligence

CVE-2026-65460: Zarinpal Gateway CSRF in WordPress plugin

CVE-2026-65460 · Severity: medium · CVSS 4.3 · Published 2026-07-23

Executive brief

The Zarinpal Gateway plugin for WordPress, which facilitates WooCommerce payments, is vulnerable to a security flaw that could allow an attacker to trick an administrator into performing unintended actions. By enticing a logged-in user to click a malicious link or visit a specially crafted webpage, an attacker could potentially modify plugin settings or perform other unauthorized tasks. This could lead to configuration changes that disrupt payment processing or compromise the integrity of the store's checkout workflow.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Zarinpal Gateway plugin (zarinpal-woocommerce-payment-gateway) for WordPress in versions up to 5.1.0. The issue stems from a lack of proper nonce validation or state-changing request verification within the plugin's administrative or configuration handlers. An unauthenticated remote attacker can exploit this by tricking a high-privileged user (such as an administrator) into visiting a malicious site or clicking a link while authenticated to the WordPress dashboard. Successful exploitation allows the attacker to execute actions on behalf of the user, such as modifying payment gateway settings. The vulnerability is addressed in version 5.1.1.

Affected products

  • Zarinpal Zarinpal Gateway (zarinpal-woocommerce-payment-gateway) <= 5.1.0

Timeline

  • 2026-06-30: other: Reported by researcher Ananda Dhakal
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD

References