S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 17, 2026

CVE-2025-13920 Scanner

CVE-2025-13920 Scanner - Information Disclosure vulnerability in WP Directory Kit

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-13920
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This makes it possible for unauthenticated attackers to extract email addresses for users with Directory Kit-specific user roles.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WP Directory Kitby wpdirectorykit
0
Updated Aug 19, 2026View on NVD →
Detail

WP Directory Kit is a WordPress plugin designed to help users create and manage business directories effortlessly. It is widely used by web developers, entrepreneurs, and small business owners who want an easy solution for building directory websites without requiring extensive coding skills. The plugin offers various features such as listings, customization options, and payment integrations. It allows users to easily set up directories for local businesses, service providers, or any niche directory website. WP Directory Kit provides a user-friendly interface that streamlines the directory creation process. It facilitates the management of large volumes of business listings, ensuring an organized and efficient directory.

The Information Disclosure vulnerability in WP Directory Kit involves unauthorized access to sensitive information due to improper access control. Specifically, the vulnerability resides in the wdk_public_action AJAX handler, which does not properly restrict access to certain endpoints. As a result, unauthenticated attackers can exploit this flaw to extract email addresses of users with Directory Kit-specific roles. This issue can lead to privacy breaches and unauthorized exposure of personal information, particularly email addresses. Proper validation and access controls are necessary to safeguard sensitive data against unauthorized access in such applications. Developers have been advised to enhance security measures to prevent unauthorized data extraction.

Technical details of this vulnerability include the exploitation of the 'wdk_public_action' AJAX action in the plugin. The vulnerability is triggered when an unauthorized request is made to this AJAX endpoint, resulting in the exposure of user email addresses. This is specifically dangerous as the endpoint returns user information without proper authentication checks. The vulnerable endpoint is '/wp-admin/admin-ajax.php' with POST parameters specifying the action and other identifiers. Attackers can send crafted requests to this endpoint to retrieve user emails associated with specific roles within the plugin. Adequate protection against this includes implementing strict access controls on AJAX actions.

If exploited, the Information Disclosure vulnerability could result in a significant privacy breach. Unauthorized attackers might collect email addresses and potentially use them for spamming, phishing, or other malicious activities. This breach can compromise user trust and lead to legal consequences for the plugin administrators, especially concerning data protection regulations. Organizations using the plugin might face reputational damage and loss of user confidence. Moreover, the exposure of contact information can be leveraged in further comprehensive attacks against user accounts.

REFERENCES

Solution Advice
  • Update WP Directory Kit to the latest version beyond 1.4.9 to address the vulnerability.
  • Verify that all AJAX endpoints are secured with proper authentication checks.
  • Regularly audit and review plugin configurations for potential security flaws.
  • Implement access control measures to limit exposure of sensitive data.
  • Educate users about potential social engineering attacks that could stem from information disclosure.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.