Zaytech

Smart Online Order For Clover

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 13.08.2026 13:37:19
  • Zuletzt bearbeitet 14.08.2026 19:09:39

Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions.

  • EPSS 0.24%
  • Veröffentlicht 27.05.2026 09:49:05
  • Zuletzt bearbeitet 27.05.2026 14:50:47

Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Authentication Bypass.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0.

  • EPSS 0.2%
  • Veröffentlicht 27.05.2026 09:49:05
  • Zuletzt bearbeitet 27.05.2026 14:50:47

Insertion of Sensitive Information Into Sent Data vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Retrieve Embedded Sensitive Data.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0.

  • EPSS 0.15%
  • Veröffentlicht 27.05.2026 09:49:04
  • Zuletzt bearbeitet 27.05.2026 14:50:47

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Stored XSS.This issue affects Smart Online Order for Clover: from n/a through <= 1...

  • EPSS 0.11%
  • Veröffentlicht 15.04.2026 15:49:53
  • Zuletzt bearbeitet 23.04.2026 15:22:54

Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cross Site Request Forgery.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0.

  • EPSS 0.62%
  • Veröffentlicht 01.11.2024 15:15:43
  • Zuletzt bearbeitet 23.04.2026 15:18:52

Missing Authorization vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders.This issue affects Smart Online Order for Clover: from n/a through <= 1.5.6.

  • EPSS 0.42%
  • Veröffentlicht 01.11.2024 15:15:43
  • Zuletzt bearbeitet 23.04.2026 15:18:52

Missing Authorization vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders.This issue affects Smart Online Order for Clover: from n/a through <= 1.5.6.

  • EPSS 0.37%
  • Veröffentlicht 16.10.2024 02:15:06
  • Zuletzt bearbeitet 11.02.2025 20:14:03

The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.5.7. This makes ...

  • EPSS 0.34%
  • Veröffentlicht 15.10.2024 09:15:03
  • Zuletzt bearbeitet 17.10.2024 20:50:03

The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo_receipt_link shortcode in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping on ...

  • EPSS 0.35%
  • Veröffentlicht 21.08.2024 06:15:10
  • Zuletzt bearbeitet 08.04.2026 18:22:29

The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.5.6. This makes it possible for authenticated att...