Klarna Order Management for WooCommerce <= 1.9.8 - Authenticated (Shop Manager+) Information Disclosure via Log Files
2025-09-03 00:00
Ananda DhakalStrategic Overview
StatusPatched in 1.9.9
Affected PluginKlarna Order Management for WooCommerce
Affected Version
<= 1.9.8CVSS2.7Low
CVE
CVE-2025-58598Vulnerability Overview
The Klarna Order Management for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.8 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.
Technical Analysis
REMEDIATION: Update to version 1.9.9, or a newer patched version --- IDENTIFIER: CWE-117 (Improper Output Neutralization for Logs) The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C