← WordPress Vulnerabilities
WordPress security by component

Clover Payment Gateway by Zaytech for WooCommerce

Clover Payment Gateway by Zaytech for WooCommerce is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: clover-payment-gateway-by-zaytech-for-woocommerce

CVE-2026-12493: Clover payment references can be replayed across WooCommerce orders

Clover Payment Gateway by Zaytech for WooCommerce before 1.3.6 does not bind an externally approved payment to the intended WooCommerce order or expected amount. An unauthenticated attacker who has one approved payment reference can replay it against arbitrary orders and cause the store to mark those orders paid without receiving the corresponding funds. The CNA record does not disclose the callback route, action, payment-reference parameter or verification function.

PublishedJul 27, 2026
Known safe version1.3.6
Safe version
Jul 27, 2026 CVE-2026-12493
Clover payment references can be replayed across WooCommerce orders
Clover Payment Gateway by Zaytech for WooCommerce before 1.3.6 does not bind an externally approved payment to the intended WooCommerce order or expected amount. An unauthenticated attacker who has one approved payment reference can replay it against arbitrary orders and cause the store to mark those orders paid without receiving the corresponding funds. The CNA record does not disclose the callback route, action, payment-reference parameter or verification function.
1.3.6
CVE7.5
NVDPending