Klarna Checkout for WooCommerce <= 2.0.9 - Arbitrary Plugin Installation, Activation and Deactivation

2020-04-08 00:00
Anonymous

Strategic Overview

Status
Patched in 2.0.10
Affected Version< 2.0.10
CVSS5.4Medium
CVEN/A
View all Kustom Checkout for WooCommerce vulnerabilities

Vulnerability Overview

The Klarna Checkout for WooCommerce plugin for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions up to, and including, 2.0.9. This is due to a missing capability check on an an important AJAX function. This makes it possible for authenticated attackers to install, activate and deactivate any plugin on the affected site.

Technical Analysis

REMEDIATION: Update to version 2.0.10, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C