Description
The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary orders as paid by replaying a single genuinely-approved payment reference (for example one obtained from their own minimal purchase).
Published: 2026-07-27
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Clover Payment Gateway by Zaytech for WooCommerce plugin older than 1.3.6 contains a flaw that fails to confirm that an approved external payment record actually corresponds to the WooCommerce order being completed. The plugin also does not verify that the paid amount matches the order total. Consequently, an unauthenticated user can replay a single legitimately approved payment reference—such as one derived from a minimal personal purchase—to mark any arbitrary order as paid. This allows the attacker to complete transactions without authorization or monetary transfer, potentially resulting in unauthorized revenue.

Affected Systems

WooCommerce sites running the Clover Payment Gateway by Zaytech plugin with a version earlier than 1.3.6 are affected. The vulnerability was identified in the plugin’s pre‑1.3.6 releases, regardless of the specific minor revision within that range. No other vendors or products were listed as impacted.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5, indicating high severity. The EPSS score is < 1%, reflecting a very low exploitation probability, and the issue is not listed in CISA KEV, implying no confirmed public exploits at present. Nevertheless, the attack can be performed by any unauthenticated user who has access to a valid external payment reference. The attacker needs only to send a crafted request to the plugin’s check_order endpoint; no authentication or privileged credentials are required. Once processed, the order is marked as paid and payment is considered complete, fully bypassing the payment gateway’s normal authorization checks. Because the flaw permits exploitation without any pre‑existing credentials, the attack surface is broad and easy to abuse.

Generated by OpenCVE AI on August 4, 2026 at 14:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Clover Payment Gateway by Zaytech plugin to version 1.3.6 or later, where the external payment reference is verified against the WooCommerce order ID and the paid amount.
  • If an immediate update is not feasible, disable or secure the check_order endpoint so that only authenticated, authorized requests can trigger payment status changes.
  • Monitor order status logs for unexpected paid flags and investigate any suspicious activity.

Generated by OpenCVE AI on August 4, 2026 at 14:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary orders as paid by replaying a single genuinely-approved payment reference (for example one obtained from their own minimal purchase).
Title Clover Payment Gateway by Zaytech for WooCommerce < 1.3.6 - Unauthenticated Payment Bypass via check_order
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-27T16:24:35.457Z

Reserved: 2026-06-17T08:29:49.750Z

Link: CVE-2026-12493

cve-icon Vulnrichment

Updated: 2026-07-27T16:24:24.822Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T07:16:24.480

Modified: 2026-07-27T20:33:01.673

Link: CVE-2026-12493

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T14:15:10Z

Weaknesses