CVE-2025-13390Active Exploitation(wpdirectorykit / wp_directory_kit)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for wpdirectorykit wp_directory_kit systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a cryptographically weak token generation mechanism. This makes it possible for unauthenticated attackers to gain administrative access and achieve full site takeover via the auto-login endpoint with a predictable token.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-303

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wp_directory_kit

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-14); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
wp_directory_kit

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-14: 1Mentions · 2026-04-20: 1PoC Mentioned / Linked · 2026-04-20: 1Active Exploitation · 2026-04-14: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-20: 104-1404-20
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-141
Active Exploitation1
2026-04-201
Disclosure1
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-13390 - critical 🚨 WP Directory Kit <= 1.4.4 - Authentication Bypass > The WP Directory Kit plugin for WordPress version 1.4.4 and below contains an authent... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-13390 @pdnuclei #NucleiTemplates #cve

    Post summary

    The message alerts to a critical authentication bypass in WP Directory Kit 1.4.4 and below, links to additional details, but provides no evidence of active exploitation, exploit code, or patch information.

    01032405
    973 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2025-13390 Exploit in the wild confirmed for CVE-2025-13390 (CVSS null). The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all ... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The text confirms that CVE-2025-13390 is being actively exploited in real-world attacks against the WordPress WP Directory Kit plugin via an authentication bypass, yet it provides no patch or PoC details.

    00000205
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwpdirectorykitwp_directory_kit-wordpress-

Explore more