The پلاگین پرداخت دلخواه WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers to make a logged in admin perform such action via a CSRF attack
https://wpscan.com/vulnerability/311e3c15-0f58-4f3b-91f8-0c62c0eea55e/