Back to search
CVE-2024-13925
Published: Apr 17, 2025
Modified: Aug 27, 2025
PUBLISHED
Description
The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint that allows an attacker to flood the log files with data at the maximum size allowed for a POST parameter per request. This can result in rapid consumption of disk space, potentially filling the entire disk.
| Vendor | Product | Versions |
|---|---|---|
Unknown | Klarna Checkout for WooCommerce | affected 0 - < 2.13.5 |
References
https://wpscan.com/vulnerability/6aebb52f-d74a-4043-86c4-c24579f24ef4/
exploit
vdb-entry
technical-description
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now