ووسلام – همگام سازی ووکامرس و باسلام
ووسلام – همگام سازی ووکامرس و باسلام has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for ووسلام – همگام سازی ووکامرس و باسلام has a vendor fix available, so running the current release closes it.
All of these findings were reported by Ananda Dhakal. ووسلام – همگام سازی ووکامرس و باسلام is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-61956sync-basalam <= 1.9.1 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

ووسلام – همگام سازی ووکامرس و باسلام
Author
hamsalam
woocommercesync basalam provides seamless two-way integration between your WooCommerce store and Basalam.com — one of the largest online marketplaces in Iran. With this plugin, you can: – Sync WooCommerce products to your Basalam vendor panel – Automatically receive and update orders from Basalam in WooCommerce – Keep product prices, inventory, and stock levels in sync in real-time Note: This plugin connects to Basalam’s external APIs. No data is sent or received until the site administrator configures their vendor credentials. توضیحات فارسی افزونهی ووسلام (همگامسازی ووکامرس و باسلام) امکان همگامسازی دوطرفه بین فروشگاه ووکامرس شما و بازار باسلام را فراهم میکند. با استفاده از این افزونه میتوانید: – محصولات ووکامرس را به غرفه باسلام اضافه و مدیریت کنید – سفارشهای ثبتشده در باسلام را به صورت خودکار در ووکامرس دریافت و مدیریت کنید – قیمت و موجودی کالاها را به صورت لحظهای همگام سازی کنید 💬 گروه پشتیبانی تلگرام 📧 ایمیل پشتیبانی 🌐 راهنمای نصب و استفاده External Services This plugin communicates with several external APIs provided and hosted by Basalam to enable synchronization between WooCommerce and Basalam. External APIs used: developers.basalam.com core.basalam.com order-processing.basalam.com categorydetection.basalam.com revision.basalam.com integration.basalam.com uploadio.basalam.com Purpose: These APIs are used for: – Syncing product information: title, description, price, inventory, images, etc. – Creating and updating orders from Basalam – Predicting product categories and validating uploaded images – Authenticating vendors and managing account credentials Data Sent (only after authentication): – Product data: title, price, stock, description, categories, images (on sync) – Order data: order ID, status, invoice number (on order updates) – Site metadata: vendor ID, domain, webhook URLs (during setup or manual sync) Data Received: – Orders placed by customers on Basalam – Product inventory updates – Vendor authentication tokens and sync status Security Measures: – All communications occur over secure HTTPS connections – No external communication happens until valid API credentials are entered – Data transfer is strictly limited to syncing functions initiated by the site administrator Terms and Privacy: This plugin depends on Basalam’s platform and services. By using the plugin, you agree to their terms and privacy policy: Basalam Terms of Service Basalam Privacy Policy Support If you need help or have questions, please contact us via: 💬 Support Telegram Group 📧 Email 🌐 Help Center
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C