Impact
The Clover Payment Gateway by Zaytech for WooCommerce plugin older than 1.3.6 contains a flaw that fails to confirm that an approved external payment record actually corresponds to the WooCommerce order being completed. The plugin also does not verify that the paid amount matches the order total. Consequently, an unauthenticated user can replay a single legitimately approved payment reference—such as one derived from a minimal personal purchase—to mark any arbitrary order as paid. This allows the attacker to complete transactions without authorization or monetary transfer, potentially resulting in unauthorized revenue.
Affected Systems
WooCommerce sites running the Clover Payment Gateway by Zaytech plugin with a version earlier than 1.3.6 are affected. The vulnerability was identified in the plugin’s pre‑1.3.6 releases, regardless of the specific minor revision within that range. No other vendors or products were listed as impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating high severity. The EPSS score is < 1%, reflecting a very low exploitation probability, and the issue is not listed in CISA KEV, implying no confirmed public exploits at present. Nevertheless, the attack can be performed by any unauthenticated user who has access to a valid external payment reference. The attacker needs only to send a crafted request to the plugin’s check_order endpoint; no authentication or privileged credentials are required. Once processed, the order is marked as paid and payment is considered complete, fully bypassing the payment gateway’s normal authorization checks. Because the flaw permits exploitation without any pre‑existing credentials, the attack surface is broad and easy to abuse.
OpenCVE Enrichment