Medium severity6.5NVD Advisory· Published Aug 21, 2024· Updated Apr 8, 2026
CVE-2024-7032
CVE-2024-7032
Description
The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'moo_deactivateAndClean' function in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to deactivate the plugin and drop all plugin tables from the database.
Affected products
1- cpe:2.3:a:zaytech:smart_online_order_for_clover:*:*:*:*:*:wordpress:*:*Range: <1.5.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.wordfence.com/threat-intel/vulnerabilities/id/9a6b05b1-c649-4b72-b884-11fb83ec77f2nvdThird Party Advisory
- plugins.trac.wordpress.org/browser/clover-online-orders/trunk/includes/moo-OnlineOrders-deactivator.phpnvdProduct
- plugins.trac.wordpress.org/browser/clover-online-orders/trunk/moo_OnlineOrders.phpnvdProduct
- plugins.trac.wordpress.org/changeset/3142846/nvd
News mentions
0No linked articles in our index yet.