Executive brief
A security flaw has been identified in the Smart Online Order for Clover plugin, which is used by businesses to manage digital food and retail orders. This vulnerability allows unauthorized individuals to bypass security checks and gain access to administrative or restricted functions. If exploited, an attacker could potentially interfere with order processing, access customer information, or disrupt business operations.
Technical details
The Smart Online Order for Clover plugin (clover-online-orders) for WordPress contains an authentication bypass vulnerability classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The flaw exists in versions up to and including 1.6.0. By utilizing an alternate path or channel that does not properly enforce authentication checks, a remote, unauthenticated attacker can bypass security controls. This could lead to unauthorized access to plugin settings or administrative functionality. Users are advised to update to the latest version of the plugin to mitigate this risk.
Affected products
- ZAYTECH Smart Online Order for Clover (clover-online-orders) n/a through 1.6.0
Timeline
- 2026-05-27: advisory: CVE-2026-42745 published