Authentication Bypass in DevKit Pro Plugin for WordPress
An authentication bypass vulnerability in the DevKit Pro WordPress plugin allows unauthenticated attackers to hijack administrator sessions via cookie manipulation and nonce collection.
CVE search metadata
CVE search record: CVE-2026-14378. Severity: critical. CVSS: 9.8. KEV: no. Product: DevKit Pro (<= 2.3.0). Brief: Authentication Bypass in DevKit Pro Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-devkit-pro-auth-bypass/
What's new
- 1. poc_available Oct 2, 07:31 via sploitus
The DevKit Pro plugin for WordPress (versions 2.3.0 and earlier) contains a critical authentication bypass vulnerability that facilitates full administrator account takeover. The flaw resides in the revert_switch handler, which incorrectly trusts an attacker-provided original_user_id cookie to define the target identity for session switching.
The plugin's logic fails to validate the requester's identity using current_user_can(), opting instead to check for the manage_options capability on the user ID specified in the cookie. Because the switch-back form and a valid, session-bound nonce are rendered in the wp_footer HTML for any visitor, an unauthenticated user can trigger the vulnerability by setting the original_user_id cookie to an administrator's ID and submitting a request with the collected nonce. Successful exploitation results in the attacker receiving an authenticated session as the targeted administrator, granting full control over the WordPress site.
Attack Chain
- Attacker visits a public-facing page of the WordPress site to trigger the rendering of the
wp_footer. - Attacker inspects the HTML source code of the
wp_footerto capture a valid, session-bound nonce. - Attacker identifies the target administrator's user ID (typically 1).
- Attacker sets the
original_user_idcookie in their browser to the captured administrator ID. - Attacker sends a POST request to the
revert_switchhandler endpoint with the valid, intercepted nonce. - The
revert_switchhandler processes the request, incorrectly trusting theoriginal_user_idcookie and verifying the capability against the administrator's account rather than the requestor's. - The system calls
wp_set_auth_cookie()using the administrator's ID, successfully authenticating the attacker as the administrator.
Impact
Successful exploitation of this vulnerability leads to complete site takeover, as the attacker gains full administrator privileges. This allows for arbitrary code execution, installation of malicious plugins, exfiltration of sensitive database content, and potential distribution of further malware to site visitors. All WordPress installations running DevKit Pro version 2.3.0 or earlier are at risk.
Recommendation
- Immediately update the DevKit Pro plugin to the latest version (post-2.3.0) to patch the
revert_switchlogic. - Audit WordPress access logs for anomalous POST requests to the
revert_switchendpoint originating from unauthenticated sessions. - Review administrative user accounts for suspicious activities or unexpected additions of new administrator accounts.
- Implement strict access controls for administrative endpoints and consider restricting access to the WordPress dashboard by IP address.
Immediate actions
Update DevKit Pro plugin to version > 2.3.0
Mitigations
Upgrade DevKit Pro to version > 2.3.0
CVE-2026-14378
Detection coverage 1
Detect CVE-2026-14378 Exploitation - Unauthorized Access to revert_switch
criticalDetects unauthorized POST requests to the revert_switch handler by unauthenticated users.
Detection queries are available on the platform. Get full rules →