CVE-2026-2592
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-2592 is an Improper Access Control vulnerability in the Zarinpal Gateway for WooCommerce WordPress plugin that allows unauthenticated attackers to fraudulently mark orders as paid without completing actual payment. The flaw affects all versions up to and including 5.0.16. It was published on February 17, 2026, and carries a CVSS v3.1 base score of 7.7 (High) (Feedly, Red Hat CVE).

Technical details

The root cause is classified as CWE-284 (Improper Access Control). The payment callback handler Return_from_ZarinPal_Gateway fails to validate that the authority token supplied in the callback URL is bound to the specific order being marked as paid. An unauthenticated attacker can reuse a valid authority token obtained from a prior legitimate transaction of the same amount to trigger payment confirmation on a different order, effectively bypassing the payment requirement entirely (Feedly, Wordfence).

Impact

Successful exploitation allows an unauthenticated attacker to obtain goods or services from a WooCommerce store without paying, causing direct financial loss to merchants. The integrity impact is high, as order payment statuses can be manipulated; availability impact is also rated high, potentially disrupting order management workflows. Confidentiality impact is low, with limited exposure of order-related data (Feedly).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the time of writing. The EPSS score is approximately 0.068%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires knowledge of a valid authority token from a prior transaction of the same amount, which adds some practical complexity (Feedly).

Exploitation steps

  1. Reconnaissance: Identify a target WooCommerce store using the Zarinpal Gateway plugin (version ≤ 5.0.16) by inspecting payment gateway references in the checkout flow or HTTP responses.
  2. Obtain a valid authority token: Complete or initiate a legitimate Zarinpal payment transaction for the same amount as the target order, capturing the Authority token returned in the payment callback URL.
  3. Identify the target order: Determine the order ID of the order to be fraudulently marked as paid (e.g., by browsing the store, placing an item in cart, or through order confirmation page enumeration).
  4. Craft a malicious callback request: Construct a callback URL to the Return_from_ZarinPal_Gateway handler, substituting the target order's identifier while supplying the previously captured valid authority token.
  5. Submit the callback: Send the crafted request to the WooCommerce site. Because the handler does not validate that the authority token belongs to the specific order, it marks the target order as paid, allowing the attacker to receive goods or services without payment (Feedly, Wordfence).

Indicators of compromise

  • Logs: WooCommerce order logs showing orders transitioning to a paid/completed status without a corresponding verified Zarinpal payment confirmation; multiple orders marked paid using the same authority token value.
  • Network: Repeated or unusual HTTP GET/POST requests to the WooCommerce payment callback endpoint (e.g., URLs containing Return_from_ZarinPal_Gateway or equivalent) from unexpected IP addresses or in rapid succession.
  • Application: Orders fulfilled for amounts that do not match any recorded Zarinpal transaction; the same Authority parameter value appearing in callback requests for multiple distinct order IDs in server access logs.

Mitigation and workarounds

Store owners should update the Zarinpal Gateway for WooCommerce plugin to a version beyond 5.0.16 that includes a fix binding authority token validation to the specific order. Until a patched version is available, consider temporarily disabling the Zarinpal payment gateway and using an alternative payment method. Merchants should also audit recent orders for anomalous payment status changes and cross-reference them against actual Zarinpal transaction records (Feedly, Wordfence).

Community reactions

Wordfence included this vulnerability in their weekly WordPress vulnerability digest for the period of February 16–22, 2026, highlighting it as a notable access control issue affecting WooCommerce payment integrity (Wordfence). The vulnerability was also noted by security aggregators including Vulners, CIRCL, and Offseq Radar shortly after disclosure. Social media activity was limited, with a brief mention on Bluesky by The Hacker Wire.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16955NONEN/A
  • ai-engine
NoYesAug 08, 2026
CVE-2026-16953NONEN/A
  • ai-engine
NoYesAug 08, 2026
CVE-2026-16948NONEN/A
  • solace-extra
NoYesAug 08, 2026
CVE-2026-16608NONEN/A
  • download-monitor
NoYesAug 08, 2026
CVE-2026-16595NONEN/A
  • wpdirectorykit
NoYesAug 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management