Record summary

CVE-2024-13925 has a selected CVSS score of 7.5 (high).

Description

The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint that allows an attacker to flood the log files with data at the maximum size allowed for a POST parameter per request. This can result in rapid consumption of disk space, potentially filling the entire disk.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 18, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Klarna Checkout for WooCommerce

Default status: unaffected

CVE ListBefore 2.13.5affected

References

2