PatchSiren

Zaytech CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Zaytech CVE published 2026-07-27

CVE-2026-12493

The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 has a vulnerability allowing unauthenticated users to mark arbitrary orders as paid. This is possible because the plugin does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total. An attacker can exploit this by repla [truncated]