افزونه پرداخت امن زرینپال برای ووکامرس (ZarinPal for WooCommerce)
افزونه پرداخت امن زرینپال برای ووکامرس (ZarinPal for WooCommerce) has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2026; all 2 are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 7.7 out of 10. Severity breakdown: 0 critical and 1 high. 2026 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Improper Access Control.
Every one of the 2 issues recorded for افزونه پرداخت امن زرینپال برای ووکامرس (ZarinPal for WooCommerce) has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. افزونه پرداخت امن زرینپال برای ووکامرس (ZarinPal for WooCommerce) is installed on roughly 60,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-2592Zarinpal Gateway for WooCommerce <= 5.0.16 - Improper Access Control to Payment Status Update
Read the full analysisVulnerability Records
افزونه پرداخت امن زرینپال برای ووکامرس (ZarinPal for WooCommerce)
Author
zarinpal
ZarinPal Payment Gateway for WooCommerce lets you easily set up the ZarinPal online payment gateway to accept payments for your WooCommerce store. Features Automatically adds the Iranian Rial, Toman, thousand-Rial, and thousand-Toman currencies to WooCommerce Simple, user-friendly settings panel Customizable messages for successful, cancelled, or failed payments Displays the ZarinPal tracking code via a shortcode Displays payment gateway errors Optional sandbox (test) mode Transaction refund support Transaction detail lookup from the order screen Choose whether the gateway fee is paid by the merchant or the customer
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C