PT-2025-47716 · WordPress · Wp Directory Kit

Tmrswrr

·

Published

2025-11-21

·

Updated

2026-02-05

·

CVE-2025-13138

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Directory Kit versions prior to 1.4.4
Description The WP Directory Kit plugin for WordPress is susceptible to SQL Injection through the columns search parameter of the select 2 ajax() function. Insufficient input sanitization and inadequate SQL query preparation allow unauthenticated attackers to inject additional SQL queries, potentially extracting sensitive information from the database.
Recommendations Update WP Directory Kit to version 1.4.4 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-13138

Affected Products

Wp Directory Kit