A critical authentication bypass (CVSS 9.8) in the DevKit Pro WordPress plugin, versions up to and including 2.3.0, lets an unauthenticated attacker get a full administrator session and take over the site.
What Is It
CVE-2026-14378 is an authentication bypass (CWE-287) in the DevKit Pro plugin for WordPress by dplugins. The bug is in the plugin's revert_switch handler, which treats the original_user_id cookie as the privileged identity. Attackers control that cookie.
The verify_nonce_and_capability() function checks the manage_options capability on the user named in the cookie. It does not check the person actually making the request through current_user_can(). When that cookie is present, the plugin also prints the switch-back form and a valid session-bound nonce through wp_footer to every visitor, including unauthenticated ones.
An attacker can:
- Set the
original_user_idcookie to any administrator's user ID. - Collect the nonce from the rendered page.
- POST that nonce back to the
revert_switchhandler.
The plugin then calls wp_set_auth_cookie() with the administrator's ID. The attacker gets an authenticated administrator session.
Why It Matters
NVD lists a CVSS 3.1 base score of 9.8 (Critical) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The attack works over the network, is low complexity, and needs no privileges and no user interaction. Confidentiality, integrity and availability impacts are all rated high.
If exploited, the attacker has full administrator access and complete control of the site.
CVE-2026-14378 has no entry in the CISA Known Exploited Vulnerabilities (KEV) catalog, so KEV does not confirm active exploitation. The NVD record is in "Deferred" status.
What's Vulnerable
- Vendor: dplugins
- Product: DevKit Pro (WordPress plugin)
- Affected versions: all versions up to and including 2.3.0
The record lists no affected CPEs.
Patch Status
The NVD record names no fixed version. It marks every version through 2.3.0 as affected and links the vendor's DevKit changelog.
Administrators running DevKit Pro 2.3.0 or earlier should:
- Check the vendor changelog and the Wordfence advisory for a release that fixes this flaw.
- Update when one is available.
- Consider disabling the plugin until a fixed version is confirmed.
There is no CISA KEV entry, so no federal required action or due date applies.