WP Directory Kit Authentication Bypass Vulnerability (CVE-2025-13390) — Critical Severity

The WP Directory Kit plugin for WordPress, a tool widely used for creating and managing online directories, has been discovered to harbor a severe security vulnerability. This critical flaw, officially cataloged as CVE-2025-13390, could allow unauthorized individuals to completely bypass the normal login process and gain full administrative control over affected WordPress websites. The root of the problem lies in a fundamental weakness within the plugin’s auto-login feature, which relies on a cryptographically insecure method for generating login tokens. This makes these tokens easily predictable by attackers, turning them into a straightforward pathway to compromise. The consequence is a potential full site takeover, underscoring the urgent need for site administrators to address this issue promptly.

CVE Details

  • Product: WP Directory Kit plugin for WordPress
  • CVE ID: CVE-2025-13390
  • Published Date: December 3, 2025
  • Severity: Critical (CVSS Score 10.0)
  • Status: Analyzed

Affected Products

This critical authentication bypass vulnerability is present in all versions of the WP Directory Kit plugin for WordPress up to, and including, version 1.4.4. If your website currently uses any of these versions, it is exposed to a significant and easily exploitable risk. Verifying your plugin versions and taking action is paramount.

Current Status

The vulnerability (CVE-2025-13390) has undergone thorough analysis and its existence has been officially confirmed. The technical details, including practical proof-of-concept exploits that demonstrate how the attack can be carried out, have been made public. This widespread disclosure highlights the immediate threat to unpatched websites and emphasizes the need for rapid remediation efforts from IT administrators and developers.

Severity Level

Assigned a “Critical” severity rating with a CVSS score of 10.0, this vulnerability signifies the highest possible level of risk. A critical rating indicates that exploiting this flaw requires minimal technical skill, no prior authentication, and directly leads to a complete compromise of the underlying system. For WordPress sites running the vulnerable WP Directory Kit plugin, this means an unauthenticated attacker can effectively gain full administrative access. Once an attacker has administrator privileges, they can perform any action a legitimate admin can: install malicious plugins, upload backdoors, deface content, steal sensitive user data, redirect visitors to malicious sites, or use your server to launch further attacks against other targets. The potential for total site takeover and the severe impact on data integrity, confidentiality, and availability cannot be overstated.

Possible Solutions

The most effective and immediate step to safeguard your WordPress site against this vulnerability is to update the WP Directory Kit plugin without delay.
It is strongly recommended that you upgrade your plugin to version 1.4.5 or any later version that includes the necessary security patches. The WordPress Trac logs indicate that a fix was implemented around the time of version 1.4.5, specifically addressing the weak token generation mechanism.

Before proceeding with any update, it is always best practice to:

  1. Perform a complete backup: Create a full, restorable backup of your entire WordPress site, including all files and the database. This critical step ensures that you can revert your site to its previous state if any unforeseen issues occur during or after the update.
  2. Test in a staging environment: If possible, first deploy the update to a non-production or staging environment. This allows you to verify that the patch resolves the vulnerability and that all other website functionalities continue to operate as expected, minimizing potential disruption to your live site.

Should an immediate update not be feasible due to operational constraints, consider temporarily deactivating the WP Directory Kit plugin as an emergency measure. Be aware that this will disable the plugin’s features. However, prioritize applying the official patch as soon as possible, as deactivation is not a long-term solution. Regularly reviewing and updating all WordPress core, themes, and plugins is a fundamental cybersecurity practice to maintain a robust defense against emerging threats.

References

https://github.com/d0n601/CVE-2025-13390
https://plugins.trac.wordpress.org/changeset/3400599/wpdirectorykit/
https://ryankozak.com/posts/cve-2025-13390/
https://www.wordfence.com/threat-intel/vulnerabilities/id/6598d171-e68c-4d2f-9cd1-f1574fa90433?source=cve
https://github.com/d0n601/CVE-2025-13390

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.