Impact
This vulnerability allows an unauthenticated user to inject malicious scripts into the WordPress Smart Online Order for Clover plugin. Based on the description, it is inferred that the flaw stems from inadequate sanitization of user‑supplied input, enabling attackers to execute arbitrary JavaScript in the browser context of any visitor. Successful exploitation could lead to session hijacking, defacement, or data exfiltration, compromising the confidentiality, integrity, and availability of the site.
Affected Systems
The affected product is the WordPress Smart Online Order for Clover plug‑in version 1.6.1 or earlier from vendor ZAYTECH. Users running any version of the plug‑in at or below 1.6.1 on a WordPress site are affected; newer versions are not vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability, but no EPSS score is available, so current exploitation probability is unclear. The vulnerability is not listed in CISA’s KEV catalog, reducing the likelihood of known exploit campaigns. The attack vector is likely web‑based, requiring no special authentication, so the vulnerability remains accessible to any visitor capable of crafting a malicious URL or form input.
OpenCVE Enrichment