The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint that allows an attacker to flood the log files with data at the maximum size allowed for a POST parameter per request. This can result in rapid consumption of disk space, potentially filling the entire disk.
History

Tue, 29 Apr 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Klarna
Klarna klarna Checkout For Woocommerce
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:klarna:klarna_checkout_for_woocommerce:*:*:*:*:*:wordpress:*:*
Vendors & Products Klarna
Klarna klarna Checkout For Woocommerce

Fri, 18 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 06:15:00 +0000

Type Values Removed Values Added
Description The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint that allows an attacker to flood the log files with data at the maximum size allowed for a POST parameter per request. This can result in rapid consumption of disk space, potentially filling the entire disk.
Title Klarna Checkout for WooCommerce < 2.13.5 - DoS via Excessive Logging
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-04-17T06:00:09.407Z

Updated: 2025-04-18T13:54:51.011Z

Reserved: 2025-03-13T12:27:53.584Z

Link: CVE-2024-13925

cve-icon Vulnrichment

Updated: 2025-04-18T13:53:14.032Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-17T06:15:43.590

Modified: 2025-04-29T19:09:09.200

Link: CVE-2024-13925

cve-icon Redhat

No data.