CVE-2026-12493

Zaytech · Clover Payment Gateway for WooCommerce

The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin contains an improper authentication vulnerability that allows unauthenticated attackers to manipulate payment processes.

Executive summary

An unauthenticated authentication bypass vulnerability in the Clover Payment Gateway for WooCommerce plugin poses a high risk to transaction integrity.

Vulnerability

The plugin suffers from an Improper Authentication flaw (CWE-287), which allows unauthenticated remote attackers to bypass security controls and potentially perform unauthorized actions within the payment gateway integration.

Business impact

Successful exploitation of this vulnerability could lead to the compromise of financial transaction integrity, potentially allowing attackers to interfere with payment processing or bypass validation. Given the CVSS score of 7.5, this high severity vulnerability necessitates immediate attention to prevent direct financial loss or reputational damage to the e-commerce platform.

Remediation

Immediate Action: Update the Clover Payment Gateway by Zaytech for WooCommerce plugin to version 1.3.6 or later immediately.

Proactive Monitoring: Review WooCommerce transaction logs for anomalous payment statuses or unauthorized order modifications originating from unknown sources.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests targeting plugin-specific endpoints until the update is applied.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

The potential for unauthorized manipulation of payment workflows makes this a critical priority for any organization utilizing this plugin. Administrators must verify the version currently in use and apply the 1.3.6 update without delay to secure the transaction environment.