plugin

Klarna Checkout For Woocommerce Vulnerabilities

6 known security issues reported for the Klarna Checkout For Woocommerce WordPress plugin. Most recent disclosed Apr 17, 2025.

2 medium

Running Klarna Checkout For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Kustom Checkout for WooCommerce [klarna-checkout-for-woocommerce] < 2.13.5

unknown

[en] The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint that allows an attacker to flood the log files with data at the maximum size allowed for a POST parameter per request. This can result in rapid consumption of disk space, potentially filling the...

Affected:
up to 2.13.5
Fixed in:
2.13.5
Disclosed:
Apr 17, 2025

CVE-2024-13925 on NVD →

Klarna Checkout for WooCommerce <= 2.13.4 - Denial of Service

medium

The Klarna Checkout for WooCommerce plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 2.13.4. This is due to kco_wc_log_js() function not restricting the size of the debug log. This makes it possible for unauthenticated attackers to fill up the log, potentially filling up the...

CVSS:
5.3
Affected:
up to 2.13.4
Fixed in:
2.13.5
Disclosed:
Mar 27, 2025

CVE-2024-13925 on NVD →

Klarna Checkout for WooCommerce <= 2.0.9 - Arbitrary Plugin Installation, Activation and Deactivation

medium

The Klarna Checkout for WooCommerce plugin for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions up to, and including, 2.0.9. This is due to a missing capability check on an an important AJAX function. This makes it possible for authenticated attackers to install, activat...

CVSS:
5.4
Affected:
up to 2.0.10
Fixed in:
2.0.10
Disclosed:
Apr 8, 2020

Kustom Checkout for WooCommerce [klarna-checkout-for-woocommerce] < 2.0.10

unknown

Authenticated Unauthorized Plugin Changes vulnerability discovered in WordPress Klarna Checkout for WooCommerce plugin (versions <= 2.0.9).

Affected:
up to 2.0.10
Fixed in:
2.0.10
Disclosed:
Apr 8, 2020

Kustom Checkout for WooCommerce [klarna-checkout-for-woocommerce] < 2.0.10

unknown

The Klarna Checkout for WooCommerce plugin for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions up to, and including, 2.0.9. This is due to a missing capability check on an an important AJAX function. This makes it possible for authenticated attackers to install, activat...

Affected:
up to 2.0.10
Fixed in:
2.0.10
Disclosed:
Apr 8, 2020

Kustom Checkout for WooCommerce [klarna-checkout-for-woocommerce] < 2.0.10

unknown

The plugin registers one AJAX action intended for installing addon plugins from WordPress.org. The callback method to this action does not have a capability nor nonce check. This enables any logged in user to post a request to the endpoint and install, activate or deactivate any plugin. Since the action is not register...

Affected:
up to 2.0.10
Fixed in:
2.0.10

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database