PatchSiren

dplugins CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL dplugins CVE published 2026-10-02

CVE-2026-14378

The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0. This vulnerability allows unauthenticated attackers to gain administrator-level access, potentially leading to complete site takeover. The `revert_switch` handler trusts the attacker-controlled `original_user_id` cookie as the privileged identity [truncated]