S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Feb 5, 2026

CVE-2025-13138 Scanner

CVE-2025-13138 Scanner - SQL Injection (SQLi) vulnerability in WP Directory Kit

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-13138
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search' parameter of the select_2_ajax() function in all versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WP Directory Kitby wpdirectorykit
0
Updated Aug 19, 2026View on NVD →
Detail

The WP Directory Kit is a plugin designed for use within WordPress that facilitates the creation of directory-based websites. It's used by web developers and business owners aiming to create directory listings, classifieds, and directory websites without extensive coding knowledge. The plugin integrates with WordPress to allow for customizations and expansions. It helps users populate directories with location-based listings, business reviews, and other directory-specific features. Due to its flexibility, the WP Directory Kit is employed in various industries and types of directory projects. Its user-friendly interface and comprehensive feature set make it a popular choice for non-technical users.

The SQL Injection vulnerability in the WP Directory Kit plugin arises from improper input sanitization in the 'columns_search' parameter of the 'select_2_ajax()' function. This flaw allows unauthenticated attackers to manipulate SQL queries executed by the plugin. The lack of sufficient escaping and preparation of SQL queries enables attackers to inject malicious SQL statements. This issue affects all plugin versions up to 1.4.3, making it possible to extract sensitive data from the WordPress database. Consequently, a vast amount of potentially sensitive user and site data could be exposed. Such vulnerabilities can lead to unauthorized data access, posing significant risks to site security and user privacy.

Technical exploitation of the SQL Injection vulnerability involves the manipulation of HTTP POST requests. By altering the 'columns_search' parameter of the 'select_2_ajax()' function, attackers can append additional SQL queries. This operation leverages a time-based blind SQL injection approach via a crafted statement that imposes a sleep delay, confirming the presence of a vulnerability. The crucial parameter lacks proper escaping, making it vulnerable to SQL statement modification. Additionally, the vulnerable component is part of an AJAX function that processes requests without authenticating the user. Therefore, it is susceptible to being exploited in web environments where the plugin is active and unpatched.

If this vulnerability is exploited, the consequences could include unauthorized access to sensitive database contents such as user credentials, emails, and other site data. The exposed data might allow attackers to compromise user accounts or manipulate site contents. Further impacts could involve data corruption or the defacing of website content. Attackers could leverage this data for further malicious activities, including phishing attacks or identity theft. Ultimately, exploitation would lead to a loss of user trust and potential damage to the site owner's reputation.

REFERENCES

Solution Advice
  • Update WP Directory Kit plugin to version 1.4.4 or later to patch the SQL injection vulnerability.
  • Implement strict input validation and escaping mechanisms on all user inputs in web applications.
  • Regularly audit and test web applications for vulnerabilities using updated security tools.
  • Educate developers on secure coding practices to prevent SQL injection and similar vulnerabilities.
  • Consider using web application firewalls to detect and block malicious SQL injection attempts in real time.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.