๐Ÿ” CVE Alert

CVE-2025-13390

CRITICAL 10.0

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

CVSS Score
10.0
EPSS Score
0.0%
EPSS Percentile
0th

The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a cryptographically weak token generation mechanism. This makes it possible for unauthenticated attackers to gain administrative access and achieve full site takeover via the auto-login endpoint with a predictable token.

CWE CWE-303
Vendor listingthemes
Product wp directory kit
Published Dec 3, 2025
Last Updated Dec 8, 2025
Stay Ahead of the Next One

Get instant alerts for listingthemes wp directory kit

Be the first to know when new critical vulnerabilities affecting listingthemes wp directory kit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

listingthemes / WP Directory Kit
1.4.0 โ‰ค 1.4.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/6598d171-e68c-4d2f-9cd1-f1574fa90433?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3400599/wpdirectorykit/ github.com: https://github.com/d0n601/CVE-2025-13390 ryankozak.com: https://ryankozak.com/posts/cve-2025-13390/

Credits

Ryan Kozak