CVE Explorer
CVE-2026-2592
The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Update in all versions up to and including 5.0.16. This is due to the payment callback handler 'Return_from_ZarinPal_Gateway' failing to validate that the authority token provided in the callback URL belongs to the specific order being marked as paid. This makes it possible for unauthenticated attackers to potentially mark orders as paid without proper payment by reusing a valid a
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Zarinpal Gateway","vendor":"zarinpal","versions":[{"lessThanOrEqual":"5.0.16","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:db9120c5f8d5ca250fb660b902b94596fc84780de43f9b06ebcf1590d221de92 · sha256:bafea355ab5ec161… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":7.7,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:db9120c5f8d5ca250fb660b902b94596fc84780de43f9b06ebcf1590d221de92 · sha256:bafea355ab5ec161… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-284","description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:db9120c5f8d5ca250fb660b902b94596fc84780de43f9b06ebcf1590d221de92 · sha256:bafea355ab5ec161… · /containers/cna/problemTypes/0/descriptions/0
Source references
7 source assertions{"url":"https://plugins.trac.wordpress.org/browser/zarinpal-woocommerce-payment-gateway/trunk/class-wc-gateway-zarinpal.php#L359"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:db9120c5f8d5ca250fb660b902b94596fc84780de43f9b06ebcf1590d221de92 · sha256:bafea355ab5ec161… · /containers/cna/references/1
{"url":"https://plugins.trac.wordpress.org/browser/zarinpal-woocommerce-payment-gateway/trunk/class-wc-gateway-zarinpal.php#L370"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:db9120c5f8d5ca250fb660b902b94596fc84780de43f9b06ebcf1590d221de92 · sha256:bafea355ab5ec161… · /containers/cna/references/2
{"url":"https://plugins.trac.wordpress.org/browser/zarinpal-woocommerce-payment-gateway/trunk/class-wc-gateway-zarinpal.php#L380"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:db9120c5f8d5ca250fb660b902b94596fc84780de43f9b06ebcf1590d221de92 · sha256:bafea355ab5ec161… · /containers/cna/references/3
{"url":"https://plugins.trac.wordpress.org/browser/zarinpal-woocommerce-payment-gateway/trunk/class-wc-gateway-zarinpal.php#L409"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:db9120c5f8d5ca250fb660b902b94596fc84780de43f9b06ebcf1590d221de92 · sha256:bafea355ab5ec161… · /containers/cna/references/4
{"url":"https://plugins.trac.wordpress.org/browser/zarinpal-woocommerce-payment-gateway/trunk/class-wc-gateway-zarinpal.php#L412"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:db9120c5f8d5ca250fb660b902b94596fc84780de43f9b06ebcf1590d221de92 · sha256:bafea355ab5ec161… · /containers/cna/references/5
{"url":"https://plugins.trac.wordpress.org/changeset/3445917/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:db9120c5f8d5ca250fb660b902b94596fc84780de43f9b06ebcf1590d221de92 · sha256:bafea355ab5ec161… · /containers/cna/references/6
{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e33fcd17-318b-408e-86bf-b4ece46121cc?source=cve"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:db9120c5f8d5ca250fb660b902b94596fc84780de43f9b06ebcf1590d221de92 · sha256:bafea355ab5ec161… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.