CyberRota Analysis
AI-GeneratedThe Persian Elementor plugin for WordPress is vulnerable to price manipulation due to a lack of server-side validation of user-supplied payment amounts, allowing unauthenticated attackers to exploit this weakness and submit arbitrary payment values to the ZarinPal payment gateway. This vulnerability affects all versions up to and including 2.8.1, posing a risk of financial fraud. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential exploitation.
Original NVD Description
The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured ZarinPal widget price. This makes it possible for unauthenticated attackers to submit arbitrary payment amounts to the ZarinPal gateway via the 'amount' parameter.