← Back to browse · API

CVE-2025-13390

Severity
CRITICAL
CVSS
10.0
EPSS
0.04661
Risk score
41.63
CISA KEV
No
PoC
No
Published
2025-12-03
Modified
2025-12-08
First seen
2026-08-07
Aliases
EUVD-2025-200972, GHSA-CMP6-J4F4-VM9F
Products
WpDirectoryKit:WP Directory Kit 1.4.0 ≤1.4.4
Sources
euvd EUVD-2025-200972

Description

The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a cryptographically weak token generation mechanism. This makes it possible for unauthenticated attackers to gain administrative access and achieve full site takeover via the auto-login endpoint with a predictable token.

References