PT-2026-104073 · WordPress · Devkit Pro

·

CVE-2026-14378

·

Published

2026-10-02

·

Updated

2026-10-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DevKit Pro versions prior to 3.0.0
Description An authentication bypass exists in the DevKit Pro plugin for WordPress. The issue occurs because the revert switch handler trusts the original user id cookie, which is controlled by the attacker, as the privileged identity. The verify nonce and capability() function incorrectly checks the manage options capability on the user identified by the cookie instead of the actual requester via current user can(). Additionally, a valid session-bound nonce and the switch-back form are publicly emitted via wp footer to any visitor, including unauthenticated users, when the cookie is present. An unauthenticated attacker can set the original user id cookie to an administrator's ID, obtain the rendered nonce, and send it to the revert switch handler. This triggers wp set auth cookie() with the administrator's ID, granting the attacker a full administrator session and complete site takeover.
Recommendations Update DevKit Pro to version 3.0.0 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14378

Affected Products

Devkit Pro