Klarna Order Management for WooCommerce <= 1.9.8 - Authenticated (Shop Manager+) Information Disclosure via Log Files

2025-09-03 00:00
Ananda Dhakal

Strategic Overview

Status
Patched in 1.9.9
Affected Version<= 1.9.8
CVSS2.7Low
CVECVE-2025-58598
View all Klarna Order Management for WooCommerce vulnerabilities

Vulnerability Overview

The Klarna Order Management for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.8 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

Technical Analysis

REMEDIATION: Update to version 1.9.9, or a newer patched version --- IDENTIFIER: CWE-117 (Improper Output Neutralization for Logs) The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C