Authentication Bypass in DevKit Pro Plugin for WordPress
CVE-2026-14378
What is CVE-2026-14378?
The DevKit Pro plugin for WordPress is susceptible to an authentication bypass that can lead to the complete takeover of administrator accounts. This vulnerability arises because the revert_switch handler incorrectly trusts the attacker-controlled original_user_id cookie as the identity of a privileged user. The function verify_nonce_and_capability() wrongly assesses the manage_options capability based on the cookie value rather than the actual user's credentials. Because related forms and session-bound nonces are exposed to all visitors via the wp_footer, unauthenticated users can exploit this weakness by manipulating the original_user_id cookie to impersonate any admin user. Attackers can then retrieve the nonce and submit it back to the revert_switch handler, allowing them to execute wp_set_auth_cookie() with the admin's ID, granting full administrative access to their session and resulting in complete control over the site.
Affected Version(s)
DevKit Pro 0 <= 2.3.0