PT-2025-16936 · Klarna · Klarna Checkout For Woocommerce

Published

2025-04-17

·

Updated

2025-04-22

·

CVE-2024-13925

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Klarna Checkout for WooCommerce versions prior to 2.13.5
Description The issue exposes an unauthenticated WooCommerce Ajax endpoint, allowing an attacker to flood log files with data, potentially consuming disk space rapidly.
Recommendations For versions prior to 2.13.5, update to version 2.13.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable WooCommerce Ajax endpoint until the update is applied.

Exploit

Fix

Related Identifiers

CVE-2024-13925

Affected Products

Klarna Checkout For Woocommerce