Skip to content
THREATWIRE

CVE

CriticalPoC Available

CVE-2026-14378

DevKit Pro unauthenticated admin takeover via revert_switch

Wordfence says DevKit Pro for WordPress through 2.3.0 lets an unauthenticated attacker forge the original_user_id cookie, harvest a public revert nonce, and obtain an administrator session via revert_switch. CVSS 3.1 9.8. A public PoC repository exists. Not in CISA KEV.

CVSS
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Class
Auth bypass
Status
PoC Available
KEV
Not in CISA KEV
0-day
No
Vendor
dplugins
Products
DevKit Pro (WordPress plugin)
Affected
All versions up to and including 2.3.0, per Wordfence.
Fixed
3.0.0 and later, per the vendor changelog referenced by Wordfence. The public changelog lists 3.0.0 after the 2.2.x line and does not spell out a 2.3.1 security note.
Published
2 Oct 2026
Updated
5 Oct 2026

The status above is the claim. Links do not upgrade it.

CVE-2026-14378 is an authentication bypass in the DevKit Pro plugin for WordPress, assigned by Wordfence. In all versions up to and including 2.3.0, the revert_switch handler trusts the attacker-controlled original_user_id cookie as the privileged identity: verify_nonce_and_capability() incorrectly checks the manage_options capability on the user identified by the cookie rather than on the actual requester via current_user_can(). When that cookie is present, the switch-back form and a valid session-bound nonce are emitted publicly via wp_footer to any visitor, including unauthenticated users. An unauthenticated attacker who sets original_user_id to an administrator's user ID can collect the rendered nonce and POST it back to revert_switch, causing wp_set_auth_cookie() to issue an administrator session and full site takeover. Wordfence classifies this as CWE-287 and scores CVSS 3.1 9.8 with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

NVD published the record on 2 October 2026 with vulnStatus Deferred. GitHub Security Advisory GHSA-xwfv-9j83-wfj7 mirrors the same score. CISA has not listed the CVE in KEV; CISA SSVC sets exploitation to none. The vendor changelog Wordfence cites lists 3.0.0 as the rebuilt release after the 2.2.x line.

A public GitHub repository owned by MRdark-ops presents a Python proof-of-concept scanner and exploit helper for this CVE. Its README and repository description name CVE-2026-14378 and DevKit Pro's user-switch revert flow; ThreatWire did not run it. This record does not reprint cookies, requests, or payloads. Exploitation in the wild is not confirmed by Wordfence or CISA.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-14378