What is CVE-2026-1982?
CVE-2026-1982: The Persian Elementor (المنتور فارسی) plugin for WordPress up to version 2.8.1 is vulnerable to Price Manipulation due to missing server-side validation of user-supplied payment amounts against the configured ZarinPal widget price. This allows attackers to alter the payment amount during transactions. Immediate update to the latest version is recommended.
Azərbaycanca: CVE-2026-1982: Persian Elementor (المنتور فارسی) WordPress plaqini 2.8.1 versiyasına qədər ZarinPal ödənişlərində server tərəfli qiymət yoxlamasının olmaması səbəbindən qiymət manipulyasiyası zəifliyinə məruz qalır. İstismar zamanı istifadəçi ödəniş məbləğini dəyişə bilər, bu da məhsul və ya xidmətlərin nəzərdə tutulandan daha ucuz əldə edilməsinə imkan yaradır. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
What does the CVE-2026-1982 vulnerability in the Persian Elementor plugin allow?
CVE-2026-1982 allows Price Manipulation because the ZarinPal payment widget does not validate the user-supplied amount against the server-side configured price. An attacker can alter the payment amount during a transaction to obtain products or services for less than the intended price.
How to protect against the CVE-2026-1982 vulnerability?
To protect against CVE-2026-1982, immediately update the Persian Elementor plugin to the latest version after 2.8.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.