Executive brief
Persian Elementor is a WordPress plugin that integrates payment processing with ZarinPal, a popular payment gateway. The plugin fails to verify that payment authorities returned from ZarinPal belong to the actual transaction being completed, allowing attackers to fraudulently complete orders by reusing payment confirmations from other transactions. This can result in order fulfillment without payment being received.
Technical details
The vulnerability is an authentication bypass in the ZarinPal payment callback handler. The plugin stores pending transactions but does not validate that the Authority parameter returned by ZarinPal in the callback matches the Authority value for the transaction being completed. An unauthenticated attacker can initiate a pending order, then replay a valid Authority from a separate paid transaction they completed earlier (matching merchant and amount), and the callback will accept verification codes 100 and 101 (which indicate already-verified payments) without re-verification. This allows order completion without payment. The attack requires no authentication and only needs a publicly accessible ZarinPal payment widget. The vulnerability was fixed in version 2.8.2.
Affected products
- Persian Elementor Persian Elementor 2.7.10 before 2.8.2
Timeline
- 2026-09-09: disclosed: Publicly disclosed
- 2026-09-11: patched: Fixed in version 2.8.2