Description

The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a cryptographically weak token generation mechanism. This makes it possible for unauthenticated attackers to gain administrative access and achieve full site takeover via the auto-login endpoint with a predictable token.

INFO

Published Date :

2025-12-03T13:52:44.263Z

Last Modified :

2025-12-08T15:59:10.552Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2025-13390 vulnerability.

Vendors Products
Listingthemes
  • Wpdirectory Kit
Wordpress
  • Wordpress
Wpdirectorykit
  • Wp Directory Kit

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact