What is CVE-2026-12493?
CVE-2026-12493 is a critical vulnerability in the Clover Payment Gateway by Zaytech for WooCommerce plugin (before 1.3.6). It fails to verify that an external payment record belongs to the specific order and matches the order total, allowing unauthenticated users to mark arbitrary orders as paid. It is strongly recommended to update the plugin to version 1.3.6 or higher immediately.
Azərbaycanca: CVE-2026-12493, Zaytech-in WooCommerce üçün Clover Payment Gateway plaginində (1.3.6-dan əvvəl) aşkarlanmış kritik boşluqdur. Bu zəiflik autentifikasiya olunmamış istifadəçilərə istənilən WooCommerce sifarişini ödənilmiş kimi qeyd etməyə imkan verir, çünki plagin xarici ödəniş qeydinin sifarişə məxsusluğunu və məbləğ uyğunluğunu yoxlamır. Dərhal plagini ən az 1.3.6 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
Which versions of the Clover Payment Gateway by Zaytech are affected by CVE-2026-12493?
This critical vulnerability affects versions of the plugin prior to 1.3.6.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.