PT-2026-104073 · WordPress · Devkit Pro
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DevKit Pro versions prior to 3.0.0
Description
An authentication bypass exists in the DevKit Pro plugin for WordPress. The issue occurs because the
revert switch handler trusts the original user id cookie, which is controlled by the attacker, as the privileged identity. The verify nonce and capability() function incorrectly checks the manage options capability on the user identified by the cookie instead of the actual requester via current user can(). Additionally, a valid session-bound nonce and the switch-back form are publicly emitted via wp footer to any visitor, including unauthenticated users, when the cookie is present. An unauthenticated attacker can set the original user id cookie to an administrator's ID, obtain the rendered nonce, and send it to the revert switch handler. This triggers wp set auth cookie() with the administrator's ID, granting the attacker a full administrator session and complete site takeover.Recommendations
Update DevKit Pro to version 3.0.0 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Devkit Pro