Clover payment references can be replayed across WooCommerce orders
Clover Payment Gateway by Zaytech for WooCommerce before 1.3.6 does not bind an externally approved payment to the intended WooCommerce order or expected amount. An unauthenticated attacker who has one approved payment reference can replay it against arbitrary orders and cause the store to mark those orders paid without receiving the corresponding funds. The CNA record does not disclose the callback route, action, payment-reference parameter or verification function.
- Component
- Clover Payment Gateway by Zaytech for WooCommerce
- Affected
- < 1.3.6
- Safe version
1.3.6- Published
- Jul 27, 2026
This CVE was published Jul 27, 2026 and is one of 1 known issue for this plugin.
Update, patch or deactivate.
Update Clover Payment Gateway by Zaytech for WooCommerce to 1.3.6 or later. Reconcile WooCommerce orders against Clover transaction IDs and amounts, investigate reused payment references and cancel or recover fraudulently fulfilled orders.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary orders as paid by replaying a single genuinely-approved payment reference (for example one obtained from their own minimal purchase).
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N