CVE-2026-14378
Received Received - Intake

Authentication Bypass in DevKit Pro Leading to Admin Takeover

Vulnerability report for CVE-2026-14378, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Wordfence

Description

The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by the cookie rather than on the actual requester via `current_user_can()`, while the switch-back form and a valid session-bound nonce are emitted publicly via `wp_footer` to any visitor β€” including unauthenticated users β€” whenever that cookie is present. This makes it possible for unauthenticated attackers to set the `original_user_id` cookie to any administrator's user ID, collect the rendered nonce, and POST it back to the `revert_switch` handler, causing `wp_set_auth_cookie()` to be called with the administrator's ID and granting the attacker a full administrator-level authenticated session and complete site takeover.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
dplugins devkit to 2.3.0 (inc)
dplugins devkit From 1.0.0 (inc) to 3.0.0 (inc)
dplugins devkit 1.6.1
dplugins devkit 1.6.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass in the DevKit Pro WordPress plugin up to version 2.3.0. It allows unauthenticated attackers to take over an administrator account by manipulating a cookie and nonce. The plugin incorrectly trusts a user-controlled cookie to determine privileges, enabling attackers to impersonate administrators and gain full site control.

Detection Guidance

Check WordPress sites for the DevKit Pro plugin versions up to 2.3.0. Look for unauthorized administrator account creation or suspicious activity in user logs. Inspect cookies for attacker-controlled original_user_id values. Review wp_footer output for exposed nonces.

Impact Analysis

If exploited, this vulnerability allows attackers to gain full administrator access to your WordPress site. This could lead to complete site takeover, unauthorized data access, modification or deletion of content, installation of malicious plugins, and potential spread to other systems if the site is part of a network.

Compliance Impact

This vulnerability could severely impact compliance with GDPR and HIPAA by allowing unauthorized access to sensitive data. GDPR requires protection of personal data, while HIPAA mandates strict controls over protected health information. A successful exploit could result in data breaches, unauthorized disclosures, and failure to meet regulatory requirements.

Mitigation Strategies

Immediately update the DevKit Pro plugin to the latest version beyond 2.3.0. Remove the plugin if unused. Audit user accounts for unauthorized administrators. Monitor for suspicious login attempts or cookie tampering.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14378. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart