
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2592 is an Improper Access Control vulnerability in the Zarinpal Gateway for WooCommerce WordPress plugin that allows unauthenticated attackers to fraudulently mark orders as paid without completing actual payment. The flaw affects all versions up to and including 5.0.16. It was published on February 17, 2026, and carries a CVSS v3.1 base score of 7.7 (High) (Feedly, Red Hat CVE).
The root cause is classified as CWE-284 (Improper Access Control). The payment callback handler Return_from_ZarinPal_Gateway fails to validate that the authority token supplied in the callback URL is bound to the specific order being marked as paid. An unauthenticated attacker can reuse a valid authority token obtained from a prior legitimate transaction of the same amount to trigger payment confirmation on a different order, effectively bypassing the payment requirement entirely (Feedly, Wordfence).
Successful exploitation allows an unauthenticated attacker to obtain goods or services from a WooCommerce store without paying, causing direct financial loss to merchants. The integrity impact is high, as order payment statuses can be manipulated; availability impact is also rated high, potentially disrupting order management workflows. Confidentiality impact is low, with limited exposure of order-related data (Feedly).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the time of writing. The EPSS score is approximately 0.068%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires knowledge of a valid authority token from a prior transaction of the same amount, which adds some practical complexity (Feedly).
Authority token returned in the payment callback URL.Return_from_ZarinPal_Gateway handler, substituting the target order's identifier while supplying the previously captured valid authority token.Return_from_ZarinPal_Gateway or equivalent) from unexpected IP addresses or in rapid succession.Authority parameter value appearing in callback requests for multiple distinct order IDs in server access logs.Store owners should update the Zarinpal Gateway for WooCommerce plugin to a version beyond 5.0.16 that includes a fix binding authority token validation to the specific order. Until a patched version is available, consider temporarily disabling the Zarinpal payment gateway and using an alternative payment method. Merchants should also audit recent orders for anomalous payment status changes and cross-reference them against actual Zarinpal transaction records (Feedly, Wordfence).
Wordfence included this vulnerability in their weekly WordPress vulnerability digest for the period of February 16–22, 2026, highlighting it as a notable access control issue affecting WooCommerce payment integrity (Wordfence). The vulnerability was also noted by security aggregators including Vulners, CIRCL, and Offseq Radar shortly after disclosure. Social media activity was limited, with a brief mention on Bluesky by The Hacker Wire.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."