CVE-2025-13920
WP Directory Kit <= 1.4.9 - Unauthenticated Email Exposure via wdk_public_action
Record summary
CVE-2025-13920 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This makes it possible for unauthenticated attackers to extract email addresses for users with Directory Kit-specific user roles.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 2, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 26, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WP Directory KitBrowse wpdirectorykit / WP Directory KitDefault status: unaffected | CVE List, VulnCheck | Through 1.4.9 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWP Directory Kit < 1.5.0 - Unauthenticated Email ExposureCVSS 6.2
WP Directory Kit plugin for WordPress <= 1.4.9 contains a sensitive information exposure caused by improper access control in wdk_public_action AJAX handler, letting unauthenticated attackers extract email addresses of users with Directory Kit-specific roles.
Impact
Unauthenticated attackers can extract email addresses of users with specific roles, leading to privacy breaches.
Remediation
Update to the latest version beyond 1.4.9.
Source: ProjectDiscovery