Authentication Bypass in WP Directory Kit Plugin for WordPress
CVE-2025-13390

10CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 December 2025

What is CVE-2025-13390?

The WP Directory Kit plugin for WordPress features a vulnerability allowing unauthorized users to bypass authentication due to a flawed token generation process in the 'wdk_generate_auto_login_link' function. This implementation relies on a cryptographically weak method, which lets unauthenticated attackers exploit the auto-login endpoint with predictable tokens. Consequently, this flaw grants them full administrative access to the website, posing a significant security risk. Users are advised to update to the latest version or implement security measures to safeguard their sites.

Affected Version(s)

WP Directory Kit 1.4.0 <= 1.4.4

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ryan Kozak
.
CVE-2025-13390 : Authentication Bypass in WP Directory Kit Plugin for WordPress