CVE-2024-43253

Missing Authorization vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders.This issue affects Smart Online Order for Clover: from n/a through <= 1.5.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zaytech:smart_online_order_for_clover:*:*:*:*:*:wordpress:*:*

History

01 Apr 2026, 16:17

Type Values Removed Values Added
Summary (en) Missing Authorization vulnerability in Zaytech Smart Online Order for Clover allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Smart Online Order for Clover: from n/a through 1.5.6. (en) Missing Authorization vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders.This issue affects Smart Online Order for Clover: from n/a through <= 1.5.6.
References
  • {'url': 'https://patchstack.com/database/vulnerability/clover-online-orders/wordpress-smart-online-order-for-clover-plugin-1-5-6-broken-access-control-vulnerability?_s_id=cve', 'tags': ['Third Party Advisory'], 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/clover-online-orders/vulnerability/wordpress-smart-online-order-for-clover-plugin-1-5-6-broken-access-control-vulnerability?_s_id=cve -
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 9.8

10 Feb 2025, 18:28

Type Values Removed Values Added
CPE cpe:2.3:a:zaytech:smart_online_order_for_clover:*:*:*:*:*:wordpress:*:*
First Time Zaytech
Zaytech smart Online Order For Clover
References () https://patchstack.com/database/vulnerability/clover-online-orders/wordpress-smart-online-order-for-clover-plugin-1-5-6-broken-access-control-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/clover-online-orders/wordpress-smart-online-order-for-clover-plugin-1-5-6-broken-access-control-vulnerability?_s_id=cve - Third Party Advisory
Summary
  • (es) La vulnerabilidad de autorización faltante en Zaytech Smart Online Order para Clover permite acceder a funcionalidades que no están correctamente restringidas por las ACL. Este problema afecta a Smart Online Order para Clover: desde n/a hasta 1.5.6.

01 Nov 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-01 15:15

Updated : 2026-04-01 16:17


NVD link : CVE-2024-43253

Mitre link : CVE-2024-43253

CVE.ORG link : CVE-2024-43253


JSON object : View

Products Affected

zaytech

  • smart_online_order_for_clover
CWE
CWE-862

Missing Authorization