Description
The WooCommerce Clover Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callback_handler function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to mark orders as paid.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16419 | The WooCommerce Clover Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callback_handler function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to mark orders as paid. |
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | WooCommerce Clover Payment Gateway <= 1.3.1 - Missing Authorization via callback_handler | |
| Weaknesses | CWE-284 |
Fri, 27 Feb 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zaytech
Zaytech woocommerce Clover Payment Gateway |
|
| CPEs | cpe:2.3:a:zaytech:woocommerce_clover_payment_gateway:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zaytech
Zaytech woocommerce Clover Payment Gateway |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:54:26.225Z
Reserved: 2024-01-16T19:43:35.724Z
Link: CVE-2024-0626
Updated: 2024-08-01T18:11:35.690Z
Status : Awaiting Analysis
Published: 2024-04-09T19:15:14.723
Modified: 2026-04-08T18:18:54.667
Link: CVE-2024-0626
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:23:29Z
Weaknesses
EUVD