Cross Site Scripting Vulnerability in Smart Online Order for Clover
CVE-2026-66700
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 August 2026
What is CVE-2026-66700?
An unauthenticated Cross Site Scripting (XSS) vulnerability exists in the Smart Online Order for Clover plugin for versions up to 1.6.1. This flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially leading to information theft, session hijacking, or other malicious activities. Users of the affected versions are advised to implement mitigations immediately.
Affected Version(s)
Smart Online Order for Clover <= 1.6.1