افزونه پرداخت امن زرینپال برای ووکامرس (ZarinPal for WooCommerce) <= 5.1.0 - Cross-Site Request Forgery
medium
The افزونه پرداخت امن زرینپال برای ووکامرس (ZarinPal for WooCommerce) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthor...
- CVSS:
- 4.3
- Affected:
- up to 5.1.0
- Fixed in:
- 5.1.1
- Disclosed:
- Jul 22, 2026
CVE-2026-65460 on NVD →
Zarinpal Gateway for WooCommerce <= 5.0.16 - Improper Access Control to Payment Status Update
high
The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Update in all versions up to and including 5.0.16. This is due to the payment callback handler 'Return_from_ZarinPal_Gateway' failing to validate that the authority token provided in the callback URL bel...
- CVSS:
- 7.7
- Affected:
- up to 5.0.16
- Fixed in:
- 5.0.17
- Disclosed:
- Feb 16, 2026
CVE-2026-2592 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database