---
id: CVE-2026-14378
title: >-
  The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass
  Leading to Administrator Account Takeover in all versions up to, and
  including, 2.3.0 This is due to the `revert_switch` handler trusting the
  attacker-controlled …
summary: >-
  The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass
  Leading to Administrator Account Takeover in all versions up to, and
  including, 2.3.0 This is due to the `revert_switch` handler trusting the
  attacker-controlled …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-287
vendor: dplugins
product: DevKit Pro
affected:
  - devkit_pro <= 2.3.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T13:18:55.613'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14378'
references:
  - url: 'https://docs.dplugins.com/devkit/changelog'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/2ab3986a-69e0-442f-8e79-35b1bc5376d9?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - exploit-available
  - cve.org
exploits:
  github: 2
  githubRepos:
    - >-
      https://github.com/anoxhunterdump-ctrl/CVE-2026-14378-DevKit-Pro-Auth-Bypass
    - 'https://github.com/murrez/CVE-2026-14378'
  checkedAt: '2026-10-02T18:58:26.681Z'
exploitAvailable: true
ingestedAt: '2026-10-02T04:09:34.547Z'
epss: 0.00479
epssPercentile: 0.39106
---

## Overview

The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by the cookie rather than on the actual requester via `current_user_can()`, while the switch-back form and a valid session-bound nonce are emitted publicly via `wp_footer` to any visitor — including unauthenticated users — whenever that cookie is present. This makes it possible for unauthenticated attackers to set the `original_user_id` cookie to any administrator's user ID, collect the rendered nonce, and POST it back to the `revert_switch` handler, causing `wp_set_auth_cookie()` to be called with the administrator's ID and granting the attacker a full administrator-level authenticated session and complete site takeover.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
