Junglewise Threat Intelligence

CVE-2026-42738: ZAYTECH Smart Online Order for Clover Stored XSS

CVE-2026-42738 · Severity: high · CVSS 7.1 · Published 2026-05-27

Technologies: Zaytech Smart Online Order for Clover. Vendors: Zaytech.

Executive brief

The Smart Online Order for Clover plugin, which allows businesses to integrate Clover point-of-sale systems with their websites, contains a security flaw. This vulnerability could allow an attacker to inject malicious scripts into the website, potentially leading to the theft of customer information or unauthorized actions on the site. Business owners using this plugin should update to the latest version to protect their customers and online operations.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the ZAYTECH Smart Online Order for Clover plugin (versions up to and including 1.6.0) due to improper neutralization of input during web page generation. An unauthenticated attacker can inject malicious scripts into the application, which are then stored and executed in the browser of any user visiting the affected page. This can lead to session hijacking, unauthorized data access, or website defacement. The vulnerability is triggered via the network and requires minimal user interaction to execute the stored payload.

Affected products

  • ZAYTECH Smart Online Order for Clover n/a through 1.6.0

Timeline

  • 2026-05-27: advisory: Vulnerability published by NVD

References

Related threats