WordPress Plugin Vulnerabilities

WP Directory Kit < 1.4.5 - Privilege Escalation via Account Takeover

Description

The plugin is vulnerable to authentication bypass due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a cryptographically weak token generation mechanism. This makes it possible for unauthenticated attackers to gain administrative access and achieve full site takeover via the auto-login endpoint with a predictable token.

Affects Plugins

Fixed in 1.4.5

References

Classification

Miscellaneous

Original Researcher
Ryan Kozak
Verified
No

Timeline

Publicly Published
2025-12-03 (about 9 months ago)
Added
2025-12-08 (about 9 months ago)
Last Updated
2025-12-08 (about 9 months ago)

Other