CVE-2026-14378 — DevKit Pro ≤2.3.0 Unauthenticated Admin Takeover (User-Switch Revert)
October 2, 2026 · 63 views
WordPress DevKit Pro (dplugins) ≤2.3.0: forged original_user_id cookie + wp_footer revert_switch nonce; verify_nonce_and_capability checks manage_options for forged user, not current requester → wp_set_auth_cookie admin session. CVSS 9.8 Critical (CWE-287). Fixed 3.0.0+. Python PoC: check (footer oracle), admin exploit, mass scan 50 threads.
Description
Overview
CVE-2026-14378 — DevKit Pro WordPress plugin (dplugins) — unauthenticated authentication bypass → full administrator session (Wordfence CNA; CVSS 3.1 9.8 Critical, CWE-287).
| | | |---|---| | Product | DevKit Pro | | Affected | ≤ 2.3.0 | | Fixed | ≥ 3.0.0 (changelog) | | Related | CVE-2026-14357 (subscriber+ theme ZIP — different bug) |
Users Manager stores prior identity in cookie original_user_id. With that cookie set, wp_footer exposes a switch-back form and nonce. revert_switch AJAX incorrectly validates manage_options against the forged user ID instead of the actual (unauthenticated) requester → wp_set_auth_cookie() for the target user.
PoC page: https://pocbit.org/pocs/cve-2026-14378
GitHub: murrez/CVE-2026-14378
CVE.org: CVE-2026-14378
Wordfence: Threat Intel
Attack chain (summary)
Cookie: original_user_id=1(or--user-id/--brute).- GET public page → parse footer for revert_switch nonce (
revert_switch,DPDEV_revert_switch, etc.). - POST
admin-ajax.phpwith action + nonce. - Verify
wordpress_logged_in_*and/wp-admin/access.
Check mode is safe: confirms switch-back material without completing takeover. Users Manager is off by default on many sites—readme ≤2.3.0 without footer nonce means feature disabled or patched.
DevKit is not on wordpress.org; fingerprint uses exposed readme.txt when present (validates Plugin Name:, not HTTP 200 alone).
Bundled tool (Python 3.9+)
Download poc.py from this page (View exploit code).
pip install requests
python poc.py check https://target.example/
python poc.py check https://target.example/ --user-id 2 --timeout 40
python poc.py admin https://target.example/
python poc.py admin https://target.example/ --user-id 1 --brute 5 --log successes.txt
python poc.py targets.txt
python poc.py targets.txt admin
Mass mode: 50 worker threads (tune in script if rate-limited).
Discovery hints (your assets only)
Commercial plugin—hunt DevKit / dplugins footprints, staging hosts, and readme under custom plugin paths when exposed.
Remediation
- Upgrade DevKit Pro to ≥ 3.0.0.
- Disable Users Manager / user switching until patched.
- Audit
admin-ajax.phpforrevert_switchwith suspiciousoriginal_user_idcookies.
See WordPress plugin vulnerabilities guide.
Legal and ethical use
Authorized security testing only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- WordPressCVE-2026-19660critical
CVE-2026-19660 — Divi Membership (DiviEngine) ≤2.3.0 paypal_param Authentication Bypass
DiviEngine Divi Membership ≤2.3.0: process_paypal_callback on init trusts base64 paypal_param GET without PayPal/IPN validation → wp_set_current_user + wp_set_auth_cookie as arbitrary user ID (incl. admin). PayPal gateway class loads even when disabled. CVSS 9.8 Critical (CWE-287). Python PoC: check/exploit, cookie export, mass scan.
- WordPressCVE-2026-87902critical
CVE-2026-87902 — WordPress Core get_page_template() Unauthenticated LFI → RCE (PEAR chain)
WordPress core 4.7.0–7.1.1: pagename from POST used in get_page_template() without validate_file(); page-templates/ traversal + PEAR gadget → RCE. GHSA-7hp8-65ch-5whp, CVSS 4.0 9.8, CWE-22. Fixed 7.1.2+ (backports 6.8.10, 7.0.6). Python mass scanner: --check, --rce, --shell. Upstream: MRdark-ops/CVE-2026-87902 (HackfutSecRoot).
- WordPressCVE-2026-18143critical
CVE-2026-18143 — Addify Request a Quote for WooCommerce Unauthenticated File Upload
Unauthenticated arbitrary file upload (CWE-434, CVSS 9.8 Critical) in Request a Quote for WooCommerce ≤ 2.9.2 via public AJAX afrfq_submit_quote_via_popup — unsafe move_uploaded_file() with attacker-controlled .php names into web-accessible RFQ temp storage. Requires popup quote rule on the storefront.
- WordPressCVE-2026-96349critical
CVE-2026-96349 — WordPress SiteSkite ≤2.1.8 API-Key Autologin + MCP eval() RCE Chain
SiteSkite WordPress plugin ≤2.1.8: long-lived API key acts as unauthenticated admin bearer via ?token= autologin; REST/admin-ajax MCP abilities run siteskite_execute_php (eval) and file write. CVSS 10.0 Critical (CWE-94). Fixed in 2.2.0. Python PoC: check (readme ≤2.1.8), exploit with API key, mass hits/exploited, --lab. Marker POCBIT-96349-OK.