CVE Database /
CVE-2024-30477
CVE · Medium
CVE-2024-30477 — Klarna for WooCommerce [klarna-payments-for-woocommerce] < 3.3.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-30477
|
Klarna for WooCommerce [klarna-payments-for-woocommerce] < 3.3.0 |
Missing Authorization |
Medium
5.3
|
< 3.3.0
|
3.3.0 |
2024-03-28 |
—
|
CVE-2024-30477
The Klarna Payments for WooCommerce plugin contained a broken access control flaw in versions before 3.3.0 that allowed unauthorized users to perform actions requiring elevated privileges due to missing authorization, authentication, or nonce verification. An attacker could exploit this vulnerability to execute administrative operations without proper permission checks. The issue was resolved in version 3.3.0 and should be addressed by updating to that release or later.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings