PT-2024-38038 · WordPress · Smart Online Order For Clover

Lucio Sá

·

Published

2024-08-20

·

Updated

2024-08-31

·

CVE-2024-7032

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions The Smart Online Order for Clover plugin for WordPress versions up to, and including, 1.5.6
Description The issue is related to a missing capability check on the moo deactivateAndClean function, which allows unauthenticated attackers to deactivate the plugin and drop all plugin tables from the database, resulting in unauthorized loss of data.
Recommendations For versions up to, and including, 1.5.6, update to a version higher than 1.5.6 to resolve the issue. As a temporary workaround, consider disabling the moo deactivateAndClean function until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-7032

Affected Products

Smart Online Order For Clover