PT-2026-64834 · Zaytech · Clover Payment Gateway
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Clover Payment Gateway by Zaytech for WooCommerce WordPress versions prior to 1.3.6
Description
The plugin fails to verify if an approved external payment record is associated with the specific WooCommerce order being completed and does not check if the paid amount matches the order total. This allows unauthenticated users to mark arbitrary orders as paid by replaying a single genuinely-approved payment reference, such as one obtained from a small personal purchase.
Recommendations
Update Clover Payment Gateway by Zaytech for WooCommerce WordPress to version 1.3.6 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clover Payment Gateway