
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13089 is an unauthenticated SQL Injection vulnerability in the WP Directory Kit plugin for WordPress, affecting all versions up to and including 1.4.7. The flaw exists in the hide_fields and attr_search parameters due to insufficient input escaping and lack of proper SQL query preparation. It was published on December 13, 2025, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Red Hat CVE, Wordfence).
The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The plugin fails to properly escape user-supplied input in the hide_fields and attr_search parameters before incorporating them into SQL queries, enabling attackers to append additional SQL statements to existing queries. Because no authentication or user interaction is required, exploitation is achievable by any remote attacker sending crafted HTTP requests to the affected WordPress site. Patch changesets are available in the WordPress plugin repository (WordPress Trac, Wordfence).
Successful exploitation allows unauthenticated remote attackers to extract sensitive information from the WordPress database, including user credentials, email addresses, configuration data, and any other stored content. The confidentiality impact is rated High, while integrity and availability are unaffected by this specific vulnerability. Extracted credentials could enable further account takeover or lateral movement within the WordPress environment (Red Hat CVE, Wordfence).
No public exploit code or active in-the-wild exploitation has been confirmed as of the available intelligence. The EPSS score is approximately 0.068%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It has been detected by Qualys (detection ID 530795) and is indexed in multiple vulnerability aggregation platforms (Qualys, Wordfence).
/wp-content/plugins/wpdirectorykit/.hide_fields or attr_search parameters via HTTP GET or POST requests.attr_search=value' UNION SELECT user_login,user_pass,NULL FROM wp_users-- -) to inject additional SQL logic into the existing query.sqlmap) to enumerate database tables and extract sensitive data such as WordPress user credentials.UNION, SELECT, FROM, --, ') in the hide_fields or attr_search query parameters targeting WP Directory Kit endpoints.wpdirectorykit tables, potentially indicating blind SQL injection timing attacks.Users should update the WP Directory Kit plugin to a version beyond 1.4.7, as patch changesets have been committed to the WordPress plugin repository (changesets 3396348 and 3412635). Until an update is applied, administrators should consider disabling the plugin or restricting access to pages that render WP Directory Kit search functionality. A web application firewall (WAF) with SQL injection rules can provide interim protection against exploitation attempts (WordPress Trac, Wordfence).
Wordfence included this vulnerability in their weekly WordPress vulnerability report for December 8–14, 2025, highlighting it as part of a broader set of plugin security issues (Wordfence Blog). RedPacket Security and several security aggregators (VulDB, Vulners, CIRCL) also published alerts shortly after disclosure. Community reaction has been limited, with no notable researcher commentary or major media coverage beyond automated vulnerability feeds.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."