Kustom Checkout for WooCommerce [klarna-checkout-for-woocommerce] < 2.13.5
unknown
[en] The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint that allows an attacker to flood the log files with data at the maximum size allowed for a POST parameter per request. This can result in rapid consumption of disk space, potentially filling the...
- Affected:
- up to 2.13.5
- Fixed in:
- 2.13.5
- Disclosed:
- Apr 17, 2025
CVE-2024-13925 on NVD →
Klarna Checkout for WooCommerce <= 2.13.4 - Denial of Service
medium
The Klarna Checkout for WooCommerce plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 2.13.4. This is due to kco_wc_log_js() function not restricting the size of the debug log. This makes it possible for unauthenticated attackers to fill up the log, potentially filling up the...
- CVSS:
- 5.3
- Affected:
- up to 2.13.4
- Fixed in:
- 2.13.5
- Disclosed:
- Mar 27, 2025
CVE-2024-13925 on NVD →
Klarna Checkout for WooCommerce <= 2.0.9 - Arbitrary Plugin Installation, Activation and Deactivation
medium
The Klarna Checkout for WooCommerce plugin for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions up to, and including, 2.0.9. This is due to a missing capability check on an an important AJAX function. This makes it possible for authenticated attackers to install, activat...
- CVSS:
- 5.4
- Affected:
- up to 2.0.10
- Fixed in:
- 2.0.10
- Disclosed:
- Apr 8, 2020
Kustom Checkout for WooCommerce [klarna-checkout-for-woocommerce] < 2.0.10
unknown
Authenticated Unauthorized Plugin Changes vulnerability discovered in WordPress Klarna Checkout for WooCommerce plugin (versions <= 2.0.9).
- Affected:
- up to 2.0.10
- Fixed in:
- 2.0.10
- Disclosed:
- Apr 8, 2020
Kustom Checkout for WooCommerce [klarna-checkout-for-woocommerce] < 2.0.10
unknown
The Klarna Checkout for WooCommerce plugin for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions up to, and including, 2.0.9. This is due to a missing capability check on an an important AJAX function. This makes it possible for authenticated attackers to install, activat...
- Affected:
- up to 2.0.10
- Fixed in:
- 2.0.10
- Disclosed:
- Apr 8, 2020
Kustom Checkout for WooCommerce [klarna-checkout-for-woocommerce] < 2.0.10
unknown
The plugin registers one AJAX action intended for installing addon plugins from WordPress.org. The callback method to this action does not have a capability nor nonce check. This enables any logged in user to post a request to the endpoint and install, activate or deactivate any plugin. Since the action is not register...
- Affected:
- up to 2.0.10
- Fixed in:
- 2.0.10
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database