Cyber & AI intelligence
Wasteland.
Briefs indexed2975
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-14378 2026-10-02

CVE-2026-14378: DevKit Pro WordPress Plugin Lets Unauthenticated Attackers Take Over Admin Accounts

"A critical authentication bypass (CVSS 9.8) in the DevKit Pro WordPress plugin, versions up to and including 2.3.0, lets an unauthenticated attacker get a full administrator session and take over the site."

A critical authentication bypass (CVSS 9.8) in the DevKit Pro WordPress plugin, versions up to and including 2.3.0, lets an unauthenticated attacker get a full administrator session and take over the site.

What Is It

CVE-2026-14378 is an authentication bypass (CWE-287) in the DevKit Pro plugin for WordPress by dplugins. The bug is in the plugin's revert_switch handler, which treats the original_user_id cookie as the privileged identity. Attackers control that cookie.

The verify_nonce_and_capability() function checks the manage_options capability on the user named in the cookie. It does not check the person actually making the request through current_user_can(). When that cookie is present, the plugin also prints the switch-back form and a valid session-bound nonce through wp_footer to every visitor, including unauthenticated ones.

An attacker can:

  1. Set the original_user_id cookie to any administrator's user ID.
  2. Collect the nonce from the rendered page.
  3. POST that nonce back to the revert_switch handler.

The plugin then calls wp_set_auth_cookie() with the administrator's ID. The attacker gets an authenticated administrator session.

Why It Matters

NVD lists a CVSS 3.1 base score of 9.8 (Critical) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The attack works over the network, is low complexity, and needs no privileges and no user interaction. Confidentiality, integrity and availability impacts are all rated high.

If exploited, the attacker has full administrator access and complete control of the site.

CVE-2026-14378 has no entry in the CISA Known Exploited Vulnerabilities (KEV) catalog, so KEV does not confirm active exploitation. The NVD record is in "Deferred" status.

What's Vulnerable

The record lists no affected CPEs.

Patch Status

The NVD record names no fixed version. It marks every version through 2.3.0 as affected and links the vendor's DevKit changelog.

Administrators running DevKit Pro 2.3.0 or earlier should:

There is no CISA KEV entry, so no federal required action or due date applies.

Sources