CVE-2025-13920
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13920 is a Sensitive Information Exposure vulnerability in the WP Directory Kit plugin for WordPress, classified under CWE-200. It affects all versions up to and including 1.4.9, allowing unauthenticated attackers to extract email addresses of users with Directory Kit-specific roles via the wdk_public_action AJAX handler. The vulnerability was published on January 24, 2026, and was reported by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, NVD).

Technical details

The root cause is improper access control on the wdk_public_action WordPress AJAX handler, which fails to enforce authentication before returning user data (CWE-200). An unauthenticated attacker can send a crafted HTTP POST request to the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) invoking the wdk_public_action action to retrieve email addresses associated with Directory Kit-specific user roles. No privileges, user interaction, or special network position are required — the attack is fully remote and low-complexity. A patch was committed to the plugin's SVN repository, visible in the changeset (WordPress Changeset, Wordfence).

Impact

Successful exploitation results in unauthorized disclosure of user email addresses for accounts assigned Directory Kit-specific roles, impacting confidentiality with no effect on integrity or availability. Harvested email addresses can be leveraged for phishing campaigns, credential stuffing, or targeted social engineering attacks against site users or administrators. The scope is limited to the affected WordPress installation, with no direct path to lateral movement or remote code execution from this vulnerability alone (Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-13920. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Nuclei templates for automated detection of this vulnerability have been added to the ProjectDiscovery nuclei-templates repository, which may facilitate opportunistic scanning (ProjectDiscovery Nuclei).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP Directory Kit plugin version ≤1.4.9 using tools like WPScan, Shodan, or automated scanners with Nuclei templates targeting this CVE.
  2. Craft the AJAX request: Prepare an unauthenticated HTTP POST request to the target site's WordPress AJAX endpoint: POST /wp-admin/admin-ajax.php with the body parameter action=wdk_public_action and any required sub-action parameters that trigger user data retrieval.
  3. Send the request: Submit the crafted request without any authentication cookies or tokens. The vulnerable handler processes the request and returns user data.
  4. Extract email addresses: Parse the JSON or HTML response to collect email addresses of users assigned Directory Kit-specific roles, which are returned without authorization checks.
  5. Leverage harvested data: Use collected email addresses for downstream attacks such as phishing, credential stuffing, or spam campaigns targeting the exposed users (Wordfence, Infinit Security).

Indicators of compromise

  • Network: Repeated unauthenticated POST requests to /wp-admin/admin-ajax.php with action=wdk_public_action in the request body from a single or rotating IP address; unusual volume of AJAX requests from non-logged-in sessions.
  • Logs: WordPress access logs showing POST /wp-admin/admin-ajax.php with action=wdk_public_action returning HTTP 200 responses to unauthenticated clients; multiple such requests in short succession from the same source IP.
  • Application: Unexpected enumeration of Directory Kit user role accounts; anomalous outbound data volume from the web server correlating with AJAX handler activity.

Mitigation and workarounds

Update the WP Directory Kit plugin to version 1.5.0 or later, which contains the fix for this vulnerability as reflected in the SVN changeset. No configuration-based workaround is available; upgrading is the only reliable remediation. Site administrators who cannot immediately update should consider temporarily deactivating the plugin or restricting access to /wp-admin/admin-ajax.php via firewall rules where feasible (WordPress Changeset, Wordfence).

Community reactions

Wordfence, the CNA for this CVE, published the vulnerability details and assigned the CVSS score. A technical write-up was published by Infinit Security detailing the unauthenticated email exposure mechanism. The vulnerability received limited broader media attention given its medium severity rating and narrow impact scope (Infinit Security, Wordfence).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management