<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:devkit:devkit_pro:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3adevkitdevkit_prowordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 04:22:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3adevkitdevkit_prowordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in DevKit Pro Plugin for WordPress</title><link>https://feed.craftedsignal.io/briefs/2026-10-devkit-pro-auth-bypass/</link><pubDate>Fri, 02 Oct 2026 04:22:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-devkit-pro-auth-bypass/</guid><description>An authentication bypass vulnerability in the DevKit Pro WordPress plugin allows unauthenticated attackers to hijack administrator sessions via cookie manipulation and nonce collection.</description><content:encoded><![CDATA[<p>The DevKit Pro plugin for WordPress (versions 2.3.0 and earlier) contains a critical authentication bypass vulnerability that facilitates full administrator account takeover. The flaw resides in the <code>revert_switch</code> handler, which incorrectly trusts an attacker-provided <code>original_user_id</code> cookie to define the target identity for session switching.</p>
<p>The plugin's logic fails to validate the requester's identity using <code>current_user_can()</code>, opting instead to check for the <code>manage_options</code> capability on the user ID specified in the cookie. Because the switch-back form and a valid, session-bound nonce are rendered in the <code>wp_footer</code> HTML for any visitor, an unauthenticated user can trigger the vulnerability by setting the <code>original_user_id</code> cookie to an administrator's ID and submitting a request with the collected nonce. Successful exploitation results in the attacker receiving an authenticated session as the targeted administrator, granting full control over the WordPress site.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker visits a public-facing page of the WordPress site to trigger the rendering of the <code>wp_footer</code>.</li>
<li>Attacker inspects the HTML source code of the <code>wp_footer</code> to capture a valid, session-bound nonce.</li>
<li>Attacker identifies the target administrator's user ID (typically 1).</li>
<li>Attacker sets the <code>original_user_id</code> cookie in their browser to the captured administrator ID.</li>
<li>Attacker sends a POST request to the <code>revert_switch</code> handler endpoint with the valid, intercepted nonce.</li>
<li>The <code>revert_switch</code> handler processes the request, incorrectly trusting the <code>original_user_id</code> cookie and verifying the capability against the administrator's account rather than the requestor's.</li>
<li>The system calls <code>wp_set_auth_cookie()</code> using the administrator's ID, successfully authenticating the attacker as the administrator.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability leads to complete site takeover, as the attacker gains full administrator privileges. This allows for arbitrary code execution, installation of malicious plugins, exfiltration of sensitive database content, and potential distribution of further malware to site visitors. All WordPress installations running DevKit Pro version 2.3.0 or earlier are at risk.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately update the DevKit Pro plugin to the latest version (post-2.3.0) to patch the <code>revert_switch</code> logic.</li>
<li>Audit WordPress access logs for anomalous POST requests to the <code>revert_switch</code> endpoint originating from unauthenticated sessions.</li>
<li>Review administrative user accounts for suspicious activities or unexpected additions of new administrator accounts.</li>
<li>Implement strict access controls for administrative endpoints and consider restricting access to the WordPress dashboard by IP address.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>