WP Directory Kit <= 1.4.4 - Authentication Bypass
CVE-2025-13390
Verified
Description
The WP Directory Kit plugin for WordPress version 1.4.4 and below contains an authentication bypass vulnerability in its auto-login functionality. The vulnerability allows unauthenticated attackers to gain administrative access by exploiting a cryptographically weak token generation mechanism that uses only the first 10 characters of MD5(user_id). For user_id=1 (typically admin), the token is always predictable.
Severity
Critical
CVSS Score
10
Exploit Probability
5%
Published Date
February 11, 2026
Template Author
maxthepm
CVE-2025-13390.yaml
10.0Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-13390
CWE ID:
cwe-287
Remediation Steps
Update to the latest version beyond 1.4.4.