Klarna Checkout for WooCommerce <= 2.13.4 - Denial of Service

2025-03-27 00:00
Anonymous

Strategic Overview

Status
Patched in 2.13.5
Affected Version<= 2.13.4
CVSS5.3Medium
CVECVE-2024-13925
View all Kustom Checkout for WooCommerce vulnerabilities

Vulnerability Overview

The Klarna Checkout for WooCommerce plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 2.13.4. This is due to kco_wc_log_js() function not restricting the size of the debug log. This makes it possible for unauthenticated attackers to fill up the log, potentially filling up the disk space and leading to a denial of service.

Technical Analysis

REMEDIATION: Update to version 2.13.5, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C