CVE-2025-15635 is a Cross-Site Request Forgery (CSRF) vulnerability affecting ZAYTECH Smart Online Order for Clover, impacting versions 1.6.0 and earlier. This flaw allows attackers to perform unauthorized actions on behalf of authenticated users through malicious web requests. The vulnerability poses a risk to e-commerce operations utilizing this Clover-integrated ordering system. The vulnerability carries a CVSS score of 4.3 (Medium severity) with a network-based attack vector requiring minimal complexity and user interaction to exploit. The attack has limited impact, affecting data integrity rather than confidentiality or availability. The EPSS score of 0.00016 indicates minimal exploitation probability relative to the broader CVE landscape. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on the Known Exploited Vulnerabilities catalog. No public exploit code has been identified, and community attention remains low, as reflected by the inactive status on security tracking lists. Organizations using this plugin should prioritize patching to versions above 1.6.0, though the immediate risk level remains modest based on current threat indicators.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.6.0CPE match | cpe:2.3:a:zaytech:smart_online_order_for_clover:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.