Reflected XSS Vulnerability in Zarinpal Paid Download by Masoud Amini
CVE-2025-22766

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
15 January 2025

Summary

The Zarinpal Paid Download plugin developed by Masoud Amini is susceptible to a reflected cross-site scripting vulnerability. This issue arises from improper neutralization of input during web page generation, allowing an attacker to inject malicious scripts into the web pages viewed by users. When users interact with these compromised links, their browsers can execute harmful scripts, potentially leading to session hijacking or unauthorized access to sensitive information. This vulnerability impacts all versions of the plugin up to and including version 2.3, emphasizing the importance of prompt updates and effective input validation measures to safeguard web applications.

Affected Version(s)

Zarinpal Paid Download <= 2.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) (Patchstack Alliance)
.