CVE-2026-14378
DevKit Pro unauthenticated admin takeover via revert_switch
Wordfence says DevKit Pro for WordPress through 2.3.0 lets an unauthenticated attacker forge the original_user_id cookie, harvest a public revert nonce, and obtain an administrator session via revert_switch. CVSS 3.1 9.8. A public PoC repository exists. Not in CISA KEV.
- CVSS
- 9.8
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Class
- Auth bypass
- Status
- PoC Available
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- dplugins
- Products
- DevKit Pro (WordPress plugin)
- Affected
- All versions up to and including 2.3.0, per Wordfence.
- Fixed
- 3.0.0 and later, per the vendor changelog referenced by Wordfence. The public changelog lists 3.0.0 after the 2.2.x line and does not spell out a 2.3.1 security note.
- CWE
- CWE-287
- Published
- 2 Oct 2026
- Updated
- 5 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2026-14378 is an authentication bypass in the DevKit Pro plugin for WordPress, assigned by Wordfence. In all versions up to and including 2.3.0, the revert_switch handler trusts the attacker-controlled original_user_id cookie as the privileged identity: verify_nonce_and_capability() incorrectly checks the manage_options capability on the user identified by the cookie rather than on the actual requester via current_user_can(). When that cookie is present, the switch-back form and a valid session-bound nonce are emitted publicly via wp_footer to any visitor, including unauthenticated users. An unauthenticated attacker who sets original_user_id to an administrator's user ID can collect the rendered nonce and POST it back to revert_switch, causing wp_set_auth_cookie() to issue an administrator session and full site takeover. Wordfence classifies this as CWE-287 and scores CVSS 3.1 9.8 with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
NVD published the record on 2 October 2026 with vulnStatus Deferred. GitHub Security Advisory GHSA-xwfv-9j83-wfj7 mirrors the same score. CISA has not listed the CVE in KEV; CISA SSVC sets exploitation to none. The vendor changelog Wordfence cites lists 3.0.0 as the rebuilt release after the 2.2.x line.
A public GitHub repository owned by MRdark-ops presents a Python proof-of-concept scanner and exploit helper for this CVE. Its README and repository description name CVE-2026-14378 and DevKit Pro's user-switch revert flow; ThreatWire did not run it. This record does not reprint cookies, requests, or payloads. Exploitation in the wild is not confirmed by Wordfence or CISA.