WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Smart Online Order for Clover

Smart Online Order for Clover allows you to receive orders from your Wordpress website and have it sent directly to your Clover POS.

14Reported vulnerabilities
7.2Highest CVSS score
1.6.4Latest version
1,000+Active installs

What to do now

Update Smart Online Order for Clover to 1.6.2 or later. 13 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 6, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2026-66700 High 7.2 0.2% 1.6.1 and earlier 1.6.2 August 10, 2026
CVE-2026-42738 High 7.2 0.2% 1.6.0 and earlier 1.6.1 May 27, 2026
CVE-2024-7032 Medium 6.5 0.5% Before 1.5.7 1.5.7 August 21, 2024
CVE-2024-29115 Medium 6.4 0.3% 1.5.5 and earlier 1.5.6 March 16, 2024
CVE-2024-8787 Medium 6.1 0.4% Before 1.5.8 1.5.8 October 16, 2024
CVE-2023-46312 Medium 6.1 0.3% 1.5.4 and earlier 1.5.5 October 22, 2023
CVE-2024-9895 Medium 5.4 0.3% Before 1.5.8 1.5.8 October 15, 2024
CVE-2024-43253 Medium 5.3 0.6% 1.5.6 and earlier 1.5.7 August 12, 2024
CVE-2026-42746 Medium 5.3 0.2% 1.6.0 and earlier 1.6.1 May 28, 2026
CVE-2026-42745 Medium 5.3 0.2% 1.6.0 and earlier 1.6.1 May 28, 2026
CVE-2025-15635 Medium 4.3 0.1% 1.6.0 and earlier April 15, 2026
CVE-2024-7030 Medium 4.3 0.4% Before 1.5.7 1.5.7 August 21, 2024
CVE-2024-43254 Medium 4.3 0.4% 1.5.6 and earlier 1.5.7 August 12, 2024
CVE-2024-31238 Medium 4.3 0.2% 1.5.4 and earlier 1.5.5 April 5, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.