Junglewise Threat Intelligence

CVE-2026-42746: ZAYTECH Smart Online Order for Clover sensitive data exposure

CVE-2026-42746 · Severity: high · CVSS 7.3 · Published 2026-05-27

Technologies: Zaytech Smart Online Order for Clover. Vendors: Zaytech.

Executive brief

A security vulnerability exists in the Smart Online Order for Clover plugin, which is used by businesses to integrate Clover point-of-sale systems with their websites. This flaw allows sensitive information to be inadvertently included in data sent by the application, potentially allowing unauthorized individuals to retrieve private data. This could lead to the exposure of customer or business information, impacting privacy and operational security.

Technical details

The ZAYTECH Smart Online Order for Clover (clover-online-orders) plugin through version 1.6.0 is vulnerable to CWE-201 (Insertion of Sensitive Information Into Sent Data). This vulnerability occurs when the application includes sensitive information in data sent to a user or third party that should not have access to that data. An unauthenticated attacker can exploit this over the network to retrieve embedded sensitive data. The CVSS score of 7.3 reflects a high impact on confidentiality, integrity, and availability, though the primary risk is data exposure. Users are advised to update to a version beyond 1.6.0 if available.

Affected products

  • ZAYTECH Smart Online Order for Clover (clover-online-orders) <= 1.6.0

Timeline

  • 2026-05-27: advisory: CVE-2026-42746 published by Patchstack and NVD

References

Related threats