plugin

Zarinpal Woocommerce Payment Gateway Vulnerabilities

2 known security issues reported for the Zarinpal Woocommerce Payment Gateway WordPress plugin. Most recent disclosed Jul 22, 2026.

1 high 1 medium

Running Zarinpal Woocommerce Payment Gateway on your site? Check whether your installed version is affected.

Scan your site free

افزونه پرداخت امن زرین‌پال برای ووکامرس (ZarinPal for WooCommerce) <= 5.1.0 - Cross-Site Request Forgery

medium

The افزونه پرداخت امن زرین‌پال برای ووکامرس (ZarinPal for WooCommerce) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthor...

CVSS:
4.3
Affected:
up to 5.1.0
Fixed in:
5.1.1
Disclosed:
Jul 22, 2026

CVE-2026-65460 on NVD →

Zarinpal Gateway for WooCommerce <= 5.0.16 - Improper Access Control to Payment Status Update

high

The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Update in all versions up to and including 5.0.16. This is due to the payment callback handler 'Return_from_ZarinPal_Gateway' failing to validate that the authority token provided in the callback URL bel...

CVSS:
7.7
Affected:
up to 5.0.16
Fixed in:
5.0.17
Disclosed:
Feb 16, 2026

CVE-2026-2592 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database