CVE-2026-65536

WordPress افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) plugin <= 4.4.5 - Cross Site Request Forgery (CSRF) vulnerability

Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.


We have discovered 625 live websites that are affected by CVE-2026-65536.

Run a Free Instant Scan




Affected Software

Product  Persian Woocommerce Shipping
Category Wordpress Plugins
Vulnerable Domains625 live websites (100% of Persian Woocommerce Shipping install base)
Vulnerable Versions
  • from 0 through 4.4.5
Vulnerable Versions Count14 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Jul 23, 2026
  • Updated - Jul 23, 2026

Credits

  • Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-65536
United States8 websites



Iran555 websites
Germany54 websites
France3 websites
Romania3 websites
Armenia2 websites

Website Distribution by TLD

Number of websites using CVE-2026-65536
.com348 websites
.net6 websites
.co5 websites
.org4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65536

Top websites that are affected by CVE-2026-65536. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com Iran***,***
******.com Iran*,***,***
*******.net Iran*,***,***
*************.com Iran*,***,***
***********.com Iran*,***,***
*****************.ir Iran*,***,***
************.com Iran*,***,***
************.com Iran*,***,***
***********.ir Iran*,***,***
*********.ir Iran*,***,***
See full domain list

FAQ

CVE-2026-65536 is Cross-Site Request Forgery (CSRF) in Persian Woocommerce Shipping
A total of 625 websites have been identified as vulnerable to CVE-2026-65536, based on global website indexing conducted by WebTechSurvey.
The Persian Woocommerce Shipping is affected by the CVE-2026-65536 vulnerability.
Persian Woocommerce Shipping versions up to and including 4.4.5 are vulnerable to CVE-2026-65536.