WP Directory Kit plugin for WordPress <= 1.4.9 contains a sensitive information exposure caused by improper access control in wdk_public_action AJAX handler, letting unauthenticated attackers extract email addresses of users with Directory Kit-specific roles.
id: CVE-2025-13920
info:
name: WP Directory Kit < 1.5.0 - Unauthenticated Email Exposure
author
...