CVE-2024-9895
Published
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo_receipt_link shortcode in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
<p><strong>NOTE:</strong> This plugin requires a Clover POS & our Clover marketplace application “Smart Online Order + WordPress” (subscription required). — Please contact us at [email protected] if you need help installing or setting up the plugin and application.</p>
<p>With <strong>Smart Online Order for Clover</strong> you can easily integrate and import your Clover inventory to show on your website in real-time. This will allow you to accept Online Orders from your website.</p>
<p>All you need is a Clover POS to easily display your menu on your website.</p>
<p>Allow customers to place orders from your website and then have the orders print to your Clover POS.</p>
<p>All orders can either automatically print or you can have the orders manually print. View all orders from your Clover POS. View daily/weekly/monthly reports from your Clover. This plugin is the ideal solution to get your business on-line in less than 10 minutes.</p>
<p>It’s also easy to do it yourself, if you get stuck, there are step by step instructions on You Tube – Search “Smart Online Order” on YouTube.</p>
<h4>How it works</h4>
<p>After installing the Smart Online Order for Clover plugin, add the pages “Order Online”, “Checkout” and “My Orders” by going to Appearance then Menu from the WordPress Dashboard. Then sync your website with your Clover POS using “Import inventory”.</p>
<p>There are also shortcodes that you can use. You would simply add the short-codes in a new post/page or an existing one.</p>
<p>If you already spent lots of time building out your Shop page using Woo-Commerce and would like to use your current Woo-Commerce inventory and then have those orders sent to the Clover – then, no worries we also have a solution for that. It is called <strong>Woo-Commerce Payment Gateway for Clover</strong>. You would still use the same app from the Clover App market “Smart Online Order” to receive your Woo-Commerce orders.</p>
<p><a href="https://wordpress.org/plugins/woo-clover-gateway-by-zaytech/" rel="ugc">Click here to use Woo-Commerce payment integration</a></p>
<p><a href="https://smartonlineorder.com/" rel="nofollow ugc">Click Here to compare the difference of whether to use your Clover Inventory or Woo-Commerce Inventory. You can also visit smartonlineorder.com</a></p>
<p>For Non-Wordpress websites, (we can create the online order page using WordPress and then you would link it to your website.<br />
The main difference of having a WordPress website is that the Online Ordering can be up and running in less than 10 minutes. Give us a call or send us an email<br />
if you don’t have a WordPress website so we can create for you the Online Ordering page so you can link it to your website.</p>
<p>If you don’t have any kind of website and don’t know where to start, give us a call or send us an email as we can make you a website with Online Ordering.</p>
<p>Below are just a few websites currently using Smart Online Order with their Clover POS.</p>
<p><a href="https://bahiabowls.com" rel="nofollow ugc">Bahia Bowls</a><br />
<a href="https://hawaiianstylegrill.smartonlineorder.com" rel="nofollow ugc">Hawaiian Style Grill</a><br />
<a href="https://www.roccosdetroit.com" rel="nofollow ugc">Rocco’s Italian Deli</a><br />
<a href="https://dareggaecafe.com" rel="nofollow ugc">DA REGGAE CAFE</a><br />
<a href="https://www.cafenune.com/" rel="nofollow ugc">CAFE NUNE</a><br />
<a href="https://www.theoriginalturkey.com" rel="nofollow ugc">Full Service Restaurant</a><br />
<a href="https://www.islandsmoothiecafe.com" rel="nofollow ugc">Island Smoothie Cafe</a><br />
<a href="https://pomodoropizzafl.com/store" rel="nofollow ugc">Pizza shop Example 1</a><br />
<a href="http://www.fastpizzaonline.com" rel="nofollow ugc">Pizza shop Example 2</a><br />
<a href="https://www.zifaros.com" rel="nofollow ugc">Pizza shop Example 3</a><br />
<a href="https://oasisgrill.com" rel="nofollow ugc">Oasis Grill </a><br />
<a href="https://nolandscakes.com" rel="nofollow ugc">Cake Shop</a><br />
<a href="https://villaromarestaurant.net" rel="nofollow ugc">Pizza Shop Example 4</a><br />
<a href="https://venuspizzeriafl.com" rel="nofollow ugc">Pizza Shop Example 5</a><br />
<a href="https://www.teabocoffee.com" rel="nofollow ugc">Coffee Shop Example 2</a><br />
<a href="https://misskellyscafe.com" rel="nofollow ugc">Another Cafe Example</a><br />
<a href="https://www.himalayanfusiononline.com" rel="nofollow ugc">Indian Food Example</a><br />
<a href="https://rucookiemunchers.com/" rel="nofollow ugc">Cookie Store Example</a><br />
<a href="https://minamisushi.com/" rel="nofollow ugc">Minami</a><br />
<a href="https://hanatea8088.smartonlineorder.com" rel="nofollow ugc">HANA TEA</a><br />
<a href="https://acmesmokedfish.smartonlineorder.com/" rel="nofollow ugc">ACME SMOKED FISH</a></p>
<p>Some websites we built, other websites were built by the merchant themselves or developers they hired.</p>