CVE-2026-2592Disclosure

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Update in all versions up to and including 5.0.16. This is due to the payment callback handler 'Return_from_ZarinPal_Gateway' failing to validate that the authority token provided in the callback URL belongs to the specific order being marked as paid. This makes it possible for unauthenticated attackers to potentially mark orders as paid without proper payment by reusing a valid authority token from a different transaction of the same amount.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-17); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-17: 2Mentions · 2026-02-22: 1Mentions · 2026-02-24: 1Patch / Workaround · 2026-02-17: 1Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-17: 2Technical Details · 2026-02-22: 1Technical Details · 2026-02-24: 102-1702-2202-24
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-172
Disclosure1Patch1
2026-02-221
Disclosure1
2026-02-241
Patch1
Full discourse4 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-2592 📊 Severity: 7.7 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2592 #CVE-2026-2592 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/InrpPmi41g

    Post summary

    The tweet announces CVE‑2026‑2592, a high‑risk vulnerability affecting WordPress with a severity score of 7.7, but provides no exploitation details, PoC, or patch information.

    0001079
    56 followersView on X
  • True Pentest Pte. Ltd.@truepentest
    Patch

    🚨 WooCommerce : Zarinpal Gateway ≤5.0.16 (CVE-2026-2592) peut entraîner un statut de paiement incorrect. Action : mettez à jour en 5.0.17 + vérifiez vos commandes récentes. https://truepentest.com/nos-ressources-en-cybersecurite/zarinpal-gateway-paiement-woocommerce/

    Post summary

    CVE‑2026‑2592 in Zarinpal Gateway for WooCommerce can cause incorrect payment status; updating to version 5.0.17 is recommended to mitigate the vulnerability.

    0000065
    689 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2592 (CVSS:7.7, HIGH) is Awaiting Analysis. The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Upd..https://nvd.nist.gov/vuln/detail/CVE-2026-2592 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-2592 is a high‑severity vulnerability in the Zarinpal Gateway for WooCommerce plugin, identified as an improper access control issue affecting payment status updates, and is currently awaiting analysis.

    0000042
    171 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH: CVE-2026-2592 in Zarinpal Gateway for WooCommerce lets attackers mark orders as paid without real payment. All plugin versions affected. Update ASAP or apply fixes! https://radar.offseq.com/threat/cve-2026-2592-cwe-284-improper-access-control-in-z-22959dc1 #OffSeq #Wor... https://t.co/BkhWGj8Ank

    Post summary

    CVE-2026-2592 in Zarinpal Gateway for WooCommerce allows attackers to mark orders as paid without real payment, affecting all versions. Users are urged to update immediately or apply vendor fixes.

    0000037
    265 followersView on X

Explore more