{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3adevkitdevkit_prowordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:devkit:devkit_pro:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-14378"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=D91F1A3B-E1FE-5659-8FD6-9FEBAFD21FA0\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["DevKit Pro (\u003c= 2.3.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress","dplugins"],"content_html":"\u003cp\u003eThe DevKit Pro plugin for WordPress (versions 2.3.0 and earlier) contains a critical authentication bypass vulnerability that facilitates full administrator account takeover. The flaw resides in the \u003ccode\u003erevert_switch\u003c/code\u003e handler, which incorrectly trusts an attacker-provided \u003ccode\u003eoriginal_user_id\u003c/code\u003e cookie to define the target identity for session switching.\u003c/p\u003e\n\u003cp\u003eThe plugin's logic fails to validate the requester's identity using \u003ccode\u003ecurrent_user_can()\u003c/code\u003e, opting instead to check for the \u003ccode\u003emanage_options\u003c/code\u003e capability on the user ID specified in the cookie. Because the switch-back form and a valid, session-bound nonce are rendered in the \u003ccode\u003ewp_footer\u003c/code\u003e HTML for any visitor, an unauthenticated user can trigger the vulnerability by setting the \u003ccode\u003eoriginal_user_id\u003c/code\u003e cookie to an administrator's ID and submitting a request with the collected nonce. Successful exploitation results in the attacker receiving an authenticated session as the targeted administrator, granting full control over the WordPress site.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker visits a public-facing page of the WordPress site to trigger the rendering of the \u003ccode\u003ewp_footer\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker inspects the HTML source code of the \u003ccode\u003ewp_footer\u003c/code\u003e to capture a valid, session-bound nonce.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the target administrator's user ID (typically 1).\u003c/li\u003e\n\u003cli\u003eAttacker sets the \u003ccode\u003eoriginal_user_id\u003c/code\u003e cookie in their browser to the captured administrator ID.\u003c/li\u003e\n\u003cli\u003eAttacker sends a POST request to the \u003ccode\u003erevert_switch\u003c/code\u003e handler endpoint with the valid, intercepted nonce.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003erevert_switch\u003c/code\u003e handler processes the request, incorrectly trusting the \u003ccode\u003eoriginal_user_id\u003c/code\u003e cookie and verifying the capability against the administrator's account rather than the requestor's.\u003c/li\u003e\n\u003cli\u003eThe system calls \u003ccode\u003ewp_set_auth_cookie()\u003c/code\u003e using the administrator's ID, successfully authenticating the attacker as the administrator.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to complete site takeover, as the attacker gains full administrator privileges. This allows for arbitrary code execution, installation of malicious plugins, exfiltration of sensitive database content, and potential distribution of further malware to site visitors. All WordPress installations running DevKit Pro version 2.3.0 or earlier are at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the DevKit Pro plugin to the latest version (post-2.3.0) to patch the \u003ccode\u003erevert_switch\u003c/code\u003e logic.\u003c/li\u003e\n\u003cli\u003eAudit WordPress access logs for anomalous POST requests to the \u003ccode\u003erevert_switch\u003c/code\u003e endpoint originating from unauthenticated sessions.\u003c/li\u003e\n\u003cli\u003eReview administrative user accounts for suspicious activities or unexpected additions of new administrator accounts.\u003c/li\u003e\n\u003cli\u003eImplement strict access controls for administrative endpoints and consider restricting access to the WordPress dashboard by IP address.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T07:31:57Z","date_published":"2026-10-02T04:22:10Z","id":"https://feed.craftedsignal.io/briefs/2026-10-devkit-pro-auth-bypass/","summary":"An authentication bypass vulnerability in the DevKit Pro WordPress plugin allows unauthenticated attackers to hijack administrator sessions via cookie manipulation and nonce collection.","title":"Authentication Bypass in DevKit Pro Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-10-devkit-pro-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:devkit:devkit_pro:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}