Unauthorized Data Modification in WooCommerce Clover Payment Gateway Plugin by Zaytech
CVE-2024-0626
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 April 2024
What is CVE-2024-0626?
The WooCommerce Clover Payment Gateway plugin allows unauthenticated attackers to manipulate order statuses by exploiting a lack of necessary permission checks within the callback_handler function. This vulnerability affects all versions up to and including 1.3.1, posing a significant risk of misuse and fraudulent activities.
Affected Version(s)
Clover Payment Gateway by Zaytech for WooCommerce 0 <= 1.3.1