CRITICAL
dplugins
CVE published 2026-10-02
CVE-2026-14378
The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0. This vulnerability allows unauthenticated attackers to gain administrator-level access, potentially leading to complete site takeover. The `revert_switch` handler trusts the attacker-controlled `original_user_id` cookie as the privileged identity [truncated]