WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
85Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 10epss 4.6%
from disclosure to weapon0 days
Published on NVDDec 3
1st PoCNov 20
VulnCheckDec 3
exploitation probability
4.6%top 9% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a cryptographically weak token generation mechanism. This makes it possible for unauthenticated attackers to gain administrative access and achieve full site takeover via the auto-login endpoint with a predictable token.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
listingthemes · WP Directory Kitpublic PoCs found — 4
githubgithub.com/Nxploited/CVE-2025-13390★ 2githubgithub.com/d0n601/CVE-2025-13390★ 0vulncheckvulncheck.com/xdb/91672417aaccunverifiedvulncheckvulncheck.com/xdb/2c7d21694afeunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.