Index
Search
Search the public record. Drafts and scheduled notes are not included.
Critical
news
DevKit Pro admin takeover is CVE-2026-14378
Wordfence disclosed CVE-2026-14378 in DevKit Pro for WordPress through 2.3.0: unauthenticated administrator session takeover via the user-switch revert flow. CVSS 9.8. A public PoC exists under a misnamed repository. Not in CISA KEV. CVE-2026-19660 is a different Divi Membership bug.
Published 3h ago
CriticalPoC Available
CVE-2026-14378
DevKit Pro unauthenticated admin takeover via revert_switch
Auth bypass
Published 4d ago