CVE-2024-7032CVSS 6.5Web
CVE-2024-7032: smart online order for clover vulnerability
The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'moo_deactivateAndClean' function in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to deactivate the plugin and drop all plugin tables from the database.
- CVSS
- 6.5 MEDIUM
- EPSS
- 38.83%
- Known exploited
- not in KEV
- Product
- smart online order for clover
What is known
The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'moo_deactivateAndClean' function in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to deactivate the plugin and drop all plugin tables from the database.