CVE-2025-13920

WP Directory Kit <= 1.4.9 - Unauthenticated Email Exposure via wdk_public_action

The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This makes it possible for unauthenticated attackers to extract email addresses for users with Directory Kit-specific user roles.


We have discovered 213 live websites that are affected by CVE-2025-13920.

Run a Free Instant Scan




Affected Software

Product  Wpdirectorykit
Category Wordpress Plugins
Vulnerable Domains213 live websites (100% of Wpdirectorykit install base)
Vulnerable Versions
  • from 0 through 1.4.9
Vulnerable Versions Count15 versions ( 88% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Jan 24, 2026
  • Updated - Jan 26, 2026

Credits

  • Sarawut Poolkhet (finder)

Website Distribution by Country

Number of websites using CVE-2025-13920
United States63 websites



Italy24 websites
Germany18 websites
Brazil7 websites
Netherlands7 websites
Cyprus7 websites
Poland6 websites
India6 websites
France6 websites
South Africa5 websites

Website Distribution by TLD

Number of websites using CVE-2025-13920
.com102 websites
.it15 websites
.com.br7 websites
.org6 websites
.de6 websites
.nl5 websites
.pl5 websites
.net3 websites
.co.uk3 websites
.com.au3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-13920

Top websites that are affected by CVE-2025-13920. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States***,***
***************.org United States***,***
************************.com Germany*,***,***
***************.com United States*,***,***
*****.nl Netherlands*,***,***
************.com United States*,***,***
******.net United States*,***,***
*******************.***.au Australia*,***,***
***************.lt Lithuania*,***,***
*********.org United States*,***,***
See full domain list

FAQ

CVE-2025-13920 is Exposure of Sensitive Information to an Unauthorized Actor in Wpdirectorykit
A total of 213 websites have been identified as vulnerable to CVE-2025-13920, based on global website indexing conducted by WebTechSurvey.
The Wpdirectorykit is affected by the CVE-2025-13920 vulnerability.
Wpdirectorykit versions up to and including 1.4.9 are vulnerable to CVE-2025-13920.