CVE-2025-13089: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13089 is an unauthenticated SQL Injection vulnerability in the WP Directory Kit plugin for WordPress, affecting all versions up to and including 1.4.7. The flaw exists in the hide_fields and attr_search parameters due to insufficient input escaping and lack of proper SQL query preparation. It was published on December 13, 2025, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Red Hat CVE, Wordfence).

Technical details

The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The plugin fails to properly escape user-supplied input in the hide_fields and attr_search parameters before incorporating them into SQL queries, enabling attackers to append additional SQL statements to existing queries. Because no authentication or user interaction is required, exploitation is achievable by any remote attacker sending crafted HTTP requests to the affected WordPress site. Patch changesets are available in the WordPress plugin repository (WordPress Trac, Wordfence).

Impact

Successful exploitation allows unauthenticated remote attackers to extract sensitive information from the WordPress database, including user credentials, email addresses, configuration data, and any other stored content. The confidentiality impact is rated High, while integrity and availability are unaffected by this specific vulnerability. Extracted credentials could enable further account takeover or lateral movement within the WordPress environment (Red Hat CVE, Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been confirmed as of the available intelligence. The EPSS score is approximately 0.068%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It has been detected by Qualys (detection ID 530795) and is indexed in multiple vulnerability aggregation platforms (Qualys, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP Directory Kit plugin (version ≤ 1.4.7) using tools like WPScan, Shodan, or by inspecting plugin directories at /wp-content/plugins/wpdirectorykit/.
  2. Identify vulnerable endpoints: Locate pages or shortcodes that render WP Directory Kit search/listing functionality, which process the hide_fields or attr_search parameters via HTTP GET or POST requests.
  3. Craft SQL injection payload: Append a malicious SQL fragment to the vulnerable parameter (e.g., attr_search=value' UNION SELECT user_login,user_pass,NULL FROM wp_users-- -) to inject additional SQL logic into the existing query.
  4. Extract database contents: Use time-based blind, error-based, or UNION-based SQL injection techniques (e.g., via sqlmap) to enumerate database tables and extract sensitive data such as WordPress user credentials.
  5. Leverage extracted data: Use harvested credentials (e.g., admin password hashes) to attempt login to the WordPress admin panel or other services, enabling further compromise (Wordfence).

Indicators of compromise

  • Network: Unusual HTTP requests containing SQL keywords (UNION, SELECT, FROM, --, ') in the hide_fields or attr_search query parameters targeting WP Directory Kit endpoints.
  • Logs: WordPress or web server access logs showing repeated requests to pages using WP Directory Kit shortcodes with anomalous parameter values; error log entries indicating SQL syntax errors from the plugin.
  • Process/Application: Unexpected database query errors or slow query log entries in MySQL/MariaDB related to the wpdirectorykit tables, potentially indicating blind SQL injection timing attacks.

Mitigation and workarounds

Users should update the WP Directory Kit plugin to a version beyond 1.4.7, as patch changesets have been committed to the WordPress plugin repository (changesets 3396348 and 3412635). Until an update is applied, administrators should consider disabling the plugin or restricting access to pages that render WP Directory Kit search functionality. A web application firewall (WAF) with SQL injection rules can provide interim protection against exploitation attempts (WordPress Trac, Wordfence).

Community reactions

Wordfence included this vulnerability in their weekly WordPress vulnerability report for December 8–14, 2025, highlighting it as part of a broader set of plugin security issues (Wordfence Blog). RedPacket Security and several security aggregators (VulDB, Vulners, CIRCL) also published alerts shortly after disclosure. Community reaction has been limited, with no notable researcher commentary or major media coverage beyond automated vulnerability feeds.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management