nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-13925 CVE-2024-13925
HIGH
Klarna Checkout for WooCommerce < 2.13.5 - DoS via Excessive Logging
Record summary
CVE-2024-13925 has a selected CVSS score of 7.5 (high).
Description
The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint that allows an attacker to flood the log files with data at the maximum size allowed for a POST parameter per request. This can result in rapid consumption of disk space, potentially filling the entire disk.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 18, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Klarna Checkout for WooCommerceDefault status: unaffected | CVE List | Before 2.13.5 | affected |
References
2wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/6aebb52f-d74a-4043-86c4-c24579f24ef4