Authentication Bypass in DevKit Pro Plugin for WordPress
CVE-2026-14378

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 October 2026

What is CVE-2026-14378?

The DevKit Pro plugin for WordPress is susceptible to an authentication bypass that can lead to the complete takeover of administrator accounts. This vulnerability arises because the revert_switch handler incorrectly trusts the attacker-controlled original_user_id cookie as the identity of a privileged user. The function verify_nonce_and_capability() wrongly assesses the manage_options capability based on the cookie value rather than the actual user's credentials. Because related forms and session-bound nonces are exposed to all visitors via the wp_footer, unauthenticated users can exploit this weakness by manipulating the original_user_id cookie to impersonate any admin user. Attackers can then retrieve the nonce and submit it back to the revert_switch handler, allowing them to execute wp_set_auth_cookie() with the admin's ID, granting full administrative access to their session and resulting in complete control over the site.

Affected Version(s)

DevKit Pro 0 <= 2.3.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

h0xilo
.