cleantalk
Vulnerabilities and Security Researches

WP Directory Kit, CVE-2025-13920

CVE, Research URL

CVE-2025-13920

Application

WP Directory Kit

Published on
Jan 24, 2026
Research Description
The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This makes it possible for unauthenticated attackers to extract email addresses for users with Directory Kit-specific user roles.
Affected versions
max 1.5.0.
Status
vulnerable