Authentication Bypass in WP Directory Kit Plugin for WordPress
CVE-2025-13390
10CRITICAL
What is CVE-2025-13390?
The WP Directory Kit plugin for WordPress features a vulnerability allowing unauthorized users to bypass authentication due to a flawed token generation process in the 'wdk_generate_auto_login_link' function. This implementation relies on a cryptographically weak method, which lets unauthenticated attackers exploit the auto-login endpoint with predictable tokens. Consequently, this flaw grants them full administrative access to the website, posing a significant security risk. Users are advised to update to the latest version or implement security measures to safeguard their sites.
Affected Version(s)
WP Directory Kit 1.4.0 <= 1.4.4
References
EPSS Score
47% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ryan Kozak