Impact
The vulnerability causes sensitive information to be written into debugging code in the Klarna Order Management for WooCommerce plugin, enabling retrieval of embedded data. This flaw can expose payment details or personal information, compromising confidentiality through a data exposure flaw identified as CWE‑215.
Affected Systems
Klarna Order Management for WooCommerce plugin for WordPress, versions from n/a through 1.9.8 inclusive.
Risk and Exploitability
The CVSS score of 6.6 reflects a moderate severity. The EPSS score of less than 1 percent indicates a very low probability of widespread exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is not explicitly defined; based on the description it is inferred that an attacker could exploit the vulnerability by triggering debugging features or accessing exposed debug output, likely requiring remote or local administrator access to the WordPress site.
OpenCVE Enrichment
EUVD