CVE-2025-13920 - WP Directory Kit <= 1.4.9 - unauthenticated email exposure via wdk_public_action

CVE-2025-13920 - WP Directory Kit <= 1.4.9 - unauthenticated email exposure via wdk_public_action

CVE ID : CVE-2025-13920 Published : Jan. 24, 2026, 12:27 p.m. | 45 minutes ago Description : The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This makes it possible for unauthenticated attackers to extract email addresses for users with Directory Kit-specific user roles. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
Jan. 24, 2026
Affected Product: WordPress