CVE-2026-1982

Persian Elementor (المنتور فارسی) <= 2.8.1 - Unauthenticated Price Manipulation via ZarinPal Widget

The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured ZarinPal widget price. This makes it possible for unauthenticated attackers to submit arbitrary payment amounts to the ZarinPal gateway via the 'amount' parameter.


We have discovered 2,109 live websites that are affected by CVE-2026-1982.

Run a Free Instant Scan




Affected Software

Product  Persian Elementor
Category Wordpress Plugins
Vulnerable Domains2,109 live websites (99% of Persian Elementor install base)
Vulnerable Versions
  • from 0 through 2.8.1
Vulnerable Versions Count16 versions ( 94% of all versions)


Common Weakness Enumeration

CWE-472 External Control of Assumed-Immutable Web Parameter



Details

  • Published - Jul 30, 2026
  • Updated - Jul 30, 2026

Credits

  • Chiao-Lin Yu (Steven Meow) (finder)

Website Distribution by Country

Number of websites using CVE-2026-1982
United States44 websites



Iran1,810 websites
Germany170 websites
France35 websites
Netherlands11 websites
Canada5 websites
Cyprus5 websites
Turkey5 websites
Armenia4 websites
GB4 websites

Website Distribution by TLD

Number of websites using CVE-2026-1982
.com1,050 websites
.net41 websites
.org36 websites
.co23 websites
.ca2 websites
.cz2 websites
.io2 websites
.com.au1 websites
.eu1 websites
.se1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-1982

Top websites that are affected by CVE-2026-1982. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.ir Iran***,***
*******.com Iran***,***
*******.com Iran***,***
******.ir Iran***,***
*******.ir Iran***,***
*******.gallery Iran***,***
******.ir Iran***,***
**********.ir Iran***,***
****.ir Iran***,***
****************.com Iran***,***
See full domain list

FAQ

CVE-2026-1982 is External Control of Assumed-Immutable Web Parameter in Persian Elementor
A total of 2,109 websites have been identified as vulnerable to CVE-2026-1982, based on global website indexing conducted by WebTechSurvey.
The Persian Elementor is affected by the CVE-2026-1982 vulnerability.
Persian Elementor versions up to and including 2.8.1 are vulnerable to CVE-2026-1982.