ZAYTECH records
10 published records for vendor zaytech.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 40%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-862 Missing Authorization4
- CWE-284 Improper Access Control1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-43253No exploit | WordPress Smart Online Order for Clover plugin <= 1.5.6 - Broken Access Control vulnerabilityzaytech · smart online order for clover · CWE-862 | Critical9.8 | — | 0.6% | Nov 1, 2024 |
35Monitor | CVE-2024-43254No exploit | WordPress Smart Online Order for Clover plugin <= 1.5.6 - Broken Access Control vulnerabilityzaytech · smart online order for clover · CWE-862 | High8.8 | — | 0.4% | Nov 1, 2024 |
35Monitor | CVE-2024-31238No exploit | WordPress Smart Online Order for Clover plugin <= 1.5.5 - Cross Site Request Forgery (CSRF) vulnerabilityzaytech · smart online order for clover · CWE-352 | High8.8 | — | 0.2% | Apr 12, 2024 |
26Monitor | CVE-2024-7032No exploit | Smart Online Order for Clover <= 1.5.6 - Missing Authorization to Plugin Deactivation and Data Deletionzaytech · smart online order for clover · CWE-862 | Medium6.5 | — | 0.5% | Aug 21, 2024 |
24Monitor | CVE-2024-8787No exploit | Smart Online Order for Clover <= 1.5.7 - Reflected Cross-Site Scriptingzaytech · smart online order for clover · CWE-79 | Medium6.1 | — | 0.4% | Oct 15, 2024 |
24Monitor | CVE-2023-46312No exploit | WordPress Smart Online Order for Clover Plugin <= 1.5.4 is vulnerable to Cross Site Scripting (XSS)zaytech · smart online order for clover · CWE-79 | Medium6.1 | — | 0.3% | Oct 31, 2023 |
21Monitor | CVE-2024-0626No exploit | WooCommerce Clover Payment Gateway <= 1.3.1 - Missing Authorization via callback_handlerelbanyaoui · clover payment gateway by zaytech for woocommerce · CWE-284 | Medium5.3 | — | 0.6% | Apr 9, 2024 |
21Monitor | CVE-2024-9895No exploit | Smart Online Order for Clover <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via moo_receipt_link Shortcodezaytech · smart online order for clover · CWE-79 | Medium5.4 | — | 0.4% | Oct 15, 2024 |
21Monitor | CVE-2024-29115No exploit | WordPress Smart Online Order for Clover plugin <= 1.5.5 - Cross Site Scripting (XSS) vulnerabilityzaytech · smart online order for clover · CWE-79 | Medium5.4 | — | 0.3% | Mar 19, 2024 |
17Monitor | CVE-2024-7030No exploit | Smart Online Order for Clover <= 1.5.6 - Missing Authorization to Authenticated (Subscriber+) Plugin Data Updatezaytech · smart online order for clover · CWE-862 | Medium4.3 | — | 0.4% | Aug 21, 2024 |
- CVE-2024-4325339Monitor
WordPress Smart Online Order for Clover plugin <= 1.5.6 - Broken Access Control vulnerability
CriticalCVSS 9.8No exploitEPSS 1%zaytech · smart online order for cloverNov 1, 2024
- CVE-2024-4325435Monitor
WordPress Smart Online Order for Clover plugin <= 1.5.6 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%zaytech · smart online order for cloverNov 1, 2024
- CVE-2024-3123835Monitor
WordPress Smart Online Order for Clover plugin <= 1.5.5 - Cross Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 0%zaytech · smart online order for cloverApr 12, 2024
- CVE-2024-703226Monitor
Smart Online Order for Clover <= 1.5.6 - Missing Authorization to Plugin Deactivation and Data Deletion
MediumCVSS 6.5No exploitEPSS 0%zaytech · smart online order for cloverAug 21, 2024
- CVE-2024-878724Monitor
Smart Online Order for Clover <= 1.5.7 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 0%zaytech · smart online order for cloverOct 15, 2024
- CVE-2023-4631224Monitor
WordPress Smart Online Order for Clover Plugin <= 1.5.4 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%zaytech · smart online order for cloverOct 31, 2023
- CVE-2024-062621Monitor
WooCommerce Clover Payment Gateway <= 1.3.1 - Missing Authorization via callback_handler
MediumCVSS 5.3No exploitEPSS 1%elbanyaoui · clover payment gateway by zaytech for woocommerceApr 9, 2024
- CVE-2024-989521Monitor
Smart Online Order for Clover <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via moo_receipt_link Shortcode
MediumCVSS 5.4No exploitEPSS 0%zaytech · smart online order for cloverOct 15, 2024
- CVE-2024-2911521Monitor
WordPress Smart Online Order for Clover plugin <= 1.5.5 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%zaytech · smart online order for cloverMar 19, 2024
- CVE-2024-703017Monitor
Smart Online Order for Clover <= 1.5.6 - Missing Authorization to Authenticated (Subscriber+) Plugin Data Update
MediumCVSS 4.3No exploitEPSS 0%zaytech · smart online order for cloverAug 21, 2024