Skip to content
THREATWIRE

News

DevKit Pro admin takeover is CVE-2026-14378

Wordfence disclosed CVE-2026-14378 in DevKit Pro for WordPress through 2.3.0: unauthenticated administrator session takeover via the user-switch revert flow. CVSS 9.8. A public PoC exists under a misnamed repository. Not in CISA KEV. CVE-2026-19660 is a different Divi Membership bug.

Critical

Published 5 Oct 2026

PoC link

On this page

What happened

On 2 October 2026 Wordfence published CVE-2026-14378 for the commercial WordPress plugin DevKit Pro (vendor dplugins). The CNA title is an unauthenticated authentication bypass to administrator account takeover via the original_user_id cookie in the frontend revert-switch flow. Wordfence scores it CVSS 3.1 9.8 and assigns CWE-287.

Social posts about this bug sometimes link a GitHub repository whose name includes CVE-2026-19660. That CVE id is a different Wordfence record: Divi Membership’s unauthenticated authentication bypass via a paypal_param parameter, not DevKit Pro.

Who is affected

Wordfence says all DevKit Pro versions up to and including 2.3.0 are affected. Sites that do not run DevKit Pro are outside this CVE. The practical path depends on the Users Manager user-switch feature that renders the switch-back UI when the cookie is present; Wordfence’s impact statement is complete site takeover once an administrator session is issued. The vendor changelog Wordfence references lists 3.0.0 as the release after the 2.2.x line.

What is confirmed

Wordfence’s CVE text confirms that revert_switch checks manage_options on the user named by the attacker-controlled original_user_id cookie instead of on the real requester, and that the switch-back form and nonce are printed in wp_footer to visitors when that cookie is set. Setting the cookie to an administrator’s ID, reading the nonce, and posting it back causes wp_set_auth_cookie() for that administrator. NVD status is Deferred. GitHub advisory GHSA-xwfv-9j83-wfj7 carries the same 9.8 score. CISA has not listed CVE-2026-14378 in KEV.

GitHub user MRdark-ops published a public repository that describes itself as a proof-of-concept scanner and exploit helper for CVE-2026-14378 against DevKit Pro’s user-switch revert flow. The repository claims it can obtain an administrator session cookie on a vulnerable site. ThreatWire did not run the project. Availability is therefore PoC.

What is not confirmed

Exploitation in the wild is not confirmed by Wordfence or CISA. The public PoC repository is named after CVE-2026-19660 even though its description and README target CVE-2026-14378; that naming mismatch is a red flag for careless packaging, not evidence that the code addresses Divi Membership. The publisher’s account also hosts many other recent CVE-titled exploit repositories. ThreatWire did not verify the PoC beyond reading its public metadata and prose, and does not treat the repo name as authoritative over Wordfence’s CVE mapping. Third-party write-ups that cite a 2.3.1 fix are not supported by the vendor changelog ThreatWire checked, which documents 3.0.0 after 2.2.x.

CVE-2026-19660 remains a separate Divi Membership issue and is not recorded as this DevKit Pro bug.

What to do

Upgrade DevKit Pro to 3.0.0 or later from the vendor. If an immediate upgrade is impossible, disable the Users Manager user-switch feature and treat any unexpected administrator sessions as hostile until the plugin is patched. After upgrading, rotate administrator credentials and review users created during the exposure window.

Sources: Wordfence Intelligence for CVE-2026-14378, NVD and CVE.org, GHSA-xwfv-9j83-wfj7, the DevKit changelog, and NVD for CVE-2026-19660 as the contrasting record.

Related CVEs

Sources

Share on X@threatwire_https://www.threatwire.tech/news/devkit-pro-admin-takeover-is-cve-2026-14378

More articles