Clover Payment Gateway by Zaytech for WooCommerce
Clover Payment Gateway by Zaytech for WooCommerce has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Improper Access Control, behind 1 of the records (50%). Other recurring categories include Improper Authentication.
Every one of the 2 issues recorded for Clover Payment Gateway by Zaytech for WooCommerce has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Clover Payment Gateway by Zaytech for WooCommerce is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2026-12493Clover Payment Gateway by Zaytech for WooCommerce <= 1.3.5 - Unauthenticated Payment Bypass
Read the full analysisVulnerability Records

Clover Payment Gateway by Zaytech for WooCommerce
Author
ZAYTECH
woocommerceWith Clover Payment Gateway by Zaytech for WooCommerce you can use your Clover POS to accept payments from your Woo-Commerce Shop Page. All you need is a Clover POS to accept payments from your Woo-Commerce / WordPress website. Allow customers to place orders from your WordPress website and then be notified of the orders on your Clover Pos. Easily manage and print the orders as they come in. This plugin is the ideal solution to accept payment through your Clover in less than 10 minutes. How it works After installing the Clover Payment Gateway by Zaytech for WooCommerce, click on payments in WooCommerce settings, then enter the Api Key. The Api Key is found by going to Clover.com “More Tools” then install the “Smart Online Order” app. Once installed, open the app to get the Api Key. Copy the Api Key and paste into the Woo-Commerce payment integration. See docs.smartonlineorder.com or search Youtube “Smart Online Order Woo Commerce” for tutorials and help. Please note: This plugin uses the existing inventory from your Woo-Commerce Store Page. It acts as a payment gateway so that payments are processed through your Clover POS. It also Auto Prints the orders that comes from your Woo Commerce website to your Clover POS. All Orders processed by the Clover can be viewed on Clover. It can also be viewed in the Woo-Commerce backend. You have full control over the orders you receive. You can manually print the receipts or have them auto print. Please remember your Woo-Commerce and your Clover Inventory are managed independently. This makes it ideal for businesses that want to use a different inventory online and a different inventory in-store. If you would like to use your Clover Inventory and not Woo-Commerce, we also have a solution for that- Visit smartonlineorder.com to compare the difference. Please remember, to get the Api Key, you must install the Smart Online Order app by going to Clover.com (from a computer), once app is installed, simply re-open the app a second time to get the Api Key. Learn more at smartonlineorder.com – You can check the PRIVACY POLICY External Services This plugin connects to the following external services: Smart Online Order API (https://api.smartonlineorders.com/, https://api-v2.smartonlineorders.com/, and sandbox equivalents) – used to authenticate your Clover merchant account, create orders, and process refunds. Terms: https://www.smartonlineorder.com/terms-of-service/ – Privacy: https://www.smartonlineorder.com/privacy-policy/ Clover Platform (https://checkout.clover.com/, https://www.clover.com/oauth/authorize, https://www.clover.com/r/) – used to tokenize cards, host checkout flows, and display Clover receipts. Legal: https://www.clover.com/legal – Privacy: https://www.clover.com/privacy-policy Google reCAPTCHA (https://www.google.com/recaptcha/api.js, https://www.google.com/recaptcha/api/siteverify) – optional anti-fraud protection for the checkout form. Terms: https://policies.google.com/terms – Privacy: https://policies.google.com/privacy WooCommerce (https://wordpress.org/plugins/woocommerce/) must be installed and active for this gateway to function.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C