Skip to content
Threat Feed
critical advisory PoC

Authentication Bypass in DevKit Pro Plugin for WordPress

An authentication bypass vulnerability in the DevKit Pro WordPress plugin allows unauthenticated attackers to hijack administrator sessions via cookie manipulation and nonce collection.

CVE search metadata

CVE search record: CVE-2026-14378. Severity: critical. CVSS: 9.8. KEV: no. Product: DevKit Pro (<= 2.3.0). Brief: Authentication Bypass in DevKit Pro Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-devkit-pro-auth-bypass/

What's new

  • 1. poc_available Oct 2, 07:31 via sploitus

The DevKit Pro plugin for WordPress (versions 2.3.0 and earlier) contains a critical authentication bypass vulnerability that facilitates full administrator account takeover. The flaw resides in the revert_switch handler, which incorrectly trusts an attacker-provided original_user_id cookie to define the target identity for session switching.

The plugin's logic fails to validate the requester's identity using current_user_can(), opting instead to check for the manage_options capability on the user ID specified in the cookie. Because the switch-back form and a valid, session-bound nonce are rendered in the wp_footer HTML for any visitor, an unauthenticated user can trigger the vulnerability by setting the original_user_id cookie to an administrator's ID and submitting a request with the collected nonce. Successful exploitation results in the attacker receiving an authenticated session as the targeted administrator, granting full control over the WordPress site.

Attack Chain

  1. Attacker visits a public-facing page of the WordPress site to trigger the rendering of the wp_footer.
  2. Attacker inspects the HTML source code of the wp_footer to capture a valid, session-bound nonce.
  3. Attacker identifies the target administrator's user ID (typically 1).
  4. Attacker sets the original_user_id cookie in their browser to the captured administrator ID.
  5. Attacker sends a POST request to the revert_switch handler endpoint with the valid, intercepted nonce.
  6. The revert_switch handler processes the request, incorrectly trusting the original_user_id cookie and verifying the capability against the administrator's account rather than the requestor's.
  7. The system calls wp_set_auth_cookie() using the administrator's ID, successfully authenticating the attacker as the administrator.

Impact

Successful exploitation of this vulnerability leads to complete site takeover, as the attacker gains full administrator privileges. This allows for arbitrary code execution, installation of malicious plugins, exfiltration of sensitive database content, and potential distribution of further malware to site visitors. All WordPress installations running DevKit Pro version 2.3.0 or earlier are at risk.

Recommendation

  • Immediately update the DevKit Pro plugin to the latest version (post-2.3.0) to patch the revert_switch logic.
  • Audit WordPress access logs for anomalous POST requests to the revert_switch endpoint originating from unauthenticated sessions.
  • Review administrative user accounts for suspicious activities or unexpected additions of new administrator accounts.
  • Implement strict access controls for administrative endpoints and consider restricting access to the WordPress dashboard by IP address.

Immediate actions

Update DevKit Pro plugin to version > 2.3.0

IT Operations 24h

Mitigations

Upgrade DevKit Pro to version > 2.3.0

immediate IT Operations

CVE-2026-14378

Detection coverage 1

Detect CVE-2026-14378 Exploitation - Unauthorized Access to revert_switch

critical

Detects unauthorized POST requests to the revert_switch handler by unauthenticated users.

sigma tactics: initial_access techniques: T1187 sources: webserver

Detection queries are available on the platform. Get full rules →