{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/devkit-pro--2.3.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:devkit_pro:devkit_pro:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-14357"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DevKit Pro (\u003c= 2.3.0)"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","rce","webserver"],"_cs_type":"advisory","_cs_vendors":["DevKit Pro"],"content_html":"\u003cp\u003eThe DevKit Pro plugin for WordPress is vulnerable to an authorization flaw identified as CVE-2026-14357. The vulnerability exists within the DPDEV_install_themes_func() function, which is registered to the wp_ajax_DPDEV_install_themes action. The function lacks proper capability checks and nonce validation, allowing any authenticated user - including those with low-privilege 'Subscriber' access - to trigger the theme installation process. By submitting a crafted request, an attacker can upload and extract an arbitrary ZIP package containing PHP files directly into the web-accessible 'wp-content/themes/' directory of the WordPress instance. Because these files are then accessible via the web server, this flaw directly facilitates remote code execution (RCE). This issue affects all versions of the DevKit Pro plugin up to and including 2.3.0.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unprivileged attacker to achieve remote code execution on the WordPress server. This could lead to full site compromise, data exfiltration, or lateral movement within the hosting environment. Organizations using affected versions of the DevKit Pro plugin are at high risk of unauthorized administrative control over their web infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately update the DevKit Pro plugin to the latest available version beyond 2.3.0 to patch CVE-2026-14357.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to monitor or block POST requests to 'wp-admin/admin-ajax.php' containing the 'action=DPDEV_install_themes' parameter if the update cannot be applied immediately.\u003c/li\u003e\n\u003cli\u003eAudit the 'wp-content/themes/' directory for any unauthorized or suspicious subdirectories or PHP files added by low-privileged user accounts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-02T07:12:31Z","date_published":"2026-09-02T07:12:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-devkit-pro-auth-bypass/","summary":"The DevKit Pro plugin for WordPress versions 2.3.0 and earlier contains an authorization vulnerability that allows authenticated attackers to perform remote code execution via arbitrary theme installation.","title":"Unauthorized Remote Code Execution in DevKit Pro Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-09-devkit-pro-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - DevKit Pro (\u003c= 2.3.0)","version":"https://jsonfeed.org/version/1.1"}