WordPress security by component
Clover Payment Gateway by Zaytech for WooCommerce
Plugin description
Clover Payment Gateway by Zaytech for WooCommerce is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.5.
Plugin slug:
clover-payment-gateway-by-zaytech-for-woocommerceLatest vulnerability
CVE-2026-12493: Clover payment references can be replayed across WooCommerce orders
Clover Payment Gateway by Zaytech for WooCommerce before 1.3.6 does not bind an externally approved payment to the intended WooCommerce order or expected amount. An unauthenticated attacker who has one approved payment reference can replay it against arbitrary orders and cause the store to mark those orders paid without receiving the corresponding funds. The CNA record does not disclose the callback route, action, payment-reference parameter or verification function.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-12493
Clover payment references can be replayed across WooCommerce orders
Clover Payment Gateway by Zaytech for WooCommerce before 1.3.6 does not bind an externally approved payment to the intended WooCommerce order or expected amount. An unauthenticated attacker who has one approved payment reference can replay it against arbitrary orders and cause the store to mark those orders paid without receiving the corresponding funds. The CNA record does not disclose the callback route, action, payment-reference parameter or verification function.
|
1.3.6 |
CVE7.5
NVDPending
|