{"id":"CVE-2026-14378","title":"The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled …","summary":"The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled …","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-287"],"vendor":"dplugins","product":"DevKit Pro","affected":["devkit_pro <= 2.3.0"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T13:18:55.613","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14378","references":[{"url":"https://docs.dplugins.com/devkit/changelog","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2ab3986a-69e0-442f-8e79-35b1bc5376d9?source=cve","label":"security@wordfence.com"}],"tags":["nvd","exploit-available","cve.org"],"exploits":{"github":2,"githubRepos":["https://github.com/anoxhunterdump-ctrl/CVE-2026-14378-DevKit-Pro-Auth-Bypass","https://github.com/murrez/CVE-2026-14378"],"checkedAt":"2026-10-02T18:58:26.681Z"},"exploitAvailable":true,"ingestedAt":"2026-10-02T04:09:34.547Z","epss":0.00479,"epssPercentile":0.39106,"slug":"CVE-2026-14378","body":"## Overview\n\nThe DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by the cookie rather than on the actual requester via `current_user_can()`, while the switch-back form and a valid session-bound nonce are emitted publicly via `wp_footer` to any visitor — including unauthenticated users — whenever that cookie is present. This makes it possible for unauthenticated attackers to set the `original_user_id` cookie to any administrator's user ID, collect the rendered nonce, and POST it back to the `revert_switch` handler, causing `wp_set_auth_cookie()` to be called with the administrator's ID and granting the attacker a full administrator-level authenticated session and complete site takeover.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":214922,"id":"CVE-2026-14378","ts":1790947203436,"field":"exploit_available","old":"false","new":"true"}]}