Authentication Bypass in WP Directory Kit Plugin for WordPress
CVE-2025-13390
10CRITICAL
What is CVE-2025-13390?
The WP Directory Kit plugin for WordPress features a vulnerability allowing unauthorized users to bypass authentication due to a flawed token generation process in the 'wdk_generate_auto_login_link' function. This implementation relies on a cryptographically weak method, which lets unauthenticated attackers exploit the auto-login endpoint with predictable tokens. Consequently, this flaw grants them full administrative access to the website, posing a significant security risk. Users are advised to update to the latest version or implement security measures to safeguard their sites.
Affected Version(s)
WP Directory Kit 1.4.0 <= 1.4.4