Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-15635

19
FAUCET Score

CVE-2025-15635 is a Cross-Site Request Forgery (CSRF) vulnerability affecting ZAYTECH Smart Online Order for Clover, impacting versions 1.6.0 and earlier. This flaw allows attackers to perform unauthorized actions on behalf of authenticated users through malicious web requests. The vulnerability poses a risk to e-commerce operations utilizing this Clover-integrated ordering system. The vulnerability carries a CVSS score of 4.3 (Medium severity) with a network-based attack vector requiring minimal complexity and user interaction to exploit. The attack has limited impact, affecting data integrity rather than confidentiality or availability. The EPSS score of 0.00016 indicates minimal exploitation probability relative to the broader CVE landscape. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on the Known Exploited Vulnerabilities catalog. No public exploit code has been identified, and community attention remains low, as reflected by the inactive status on security tracking lists. Organizations using this plugin should prioritize patching to versions above 1.6.0, though the immediate risk level remains modest based on current threat indicators.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, <= 1.6.0CPE match
cpe:2.3:a:zaytech:smart_online_order_for_clover:*:*:*:*:*:wordpress:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.11%
Probability of exploitation in next 30 days
EPSS Percentile
1.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0011 is in the 0th percentile among its peer group of 26,234 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

patchstack.com / database/Wordpress/Plugin/clover-online-orders/vulnerability/wordpress-smart-online-order-for-clover-plugin-1-6-0-cross-site-request-forgery-csrf-vulnerability