Sceawere
Vulnerability Detail
CVE-2026-14378UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
DevKit Pro Authentication Bypass
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 19h ago
- Vendor
- dplugins
- Product
- DevKit Pro
- Attack Type
- CWE-287 Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by the cookie rather than on the actual requester via `current_user_can()`, while the switch-back form and a valid session-bound nonce are emitted publicly via `wp_footer` to any visitor — including unauthenticated users — whenever that cookie is present. This makes it possible for unauthenticated attackers to set the `original_user_id` cookie to any administrator's user ID, collect the rendered nonce, and POST it back to the `revert_switch` handler, causing `wp_set_auth_cookie()` to be called with the administrator's ID and granting the attacker a full administrator-level authenticated session and complete site takeover.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-02T04:18:06.277Z",
"pubdate": "2026-10-02T04:18:06.277Z",
"executiveSummary": "The DevKit Pro plugin for WordPress, in versions up to and including 2.3.0, contains a critical authentication bypass vulnerability that permits an unauthenticated attacker to achieve a complete administrator account takeover.\nThe vulnerability originates from the insecure handling of the 'original_user_id' cookie within the 'revert_switch' function. By failing to validate the requestor's current session against required administrative capabilities, the plugin incorrectly grants authorization based on user-supplied input.\nAn attacker can exploit this by manipulating cookies and harvesting nonces rendered in the site's footer to hijack any administrative account, including those of site owners.\nThe impact of this vulnerability is total system compromise, as it grants the attacker full administrative access to the WordPress environment. Exploitation is trivial, requiring no prior authentication or administrative privileges, and can be performed remotely via standard HTTP requests. Given the severity, this represents a critical risk to site integrity, data confidentiality, and availability.",
"technicalDetails": "The vulnerability resides in the 'revert_switch' handler of the DevKit Pro plugin. The root cause is a flawed implementation of 'verify_nonce_and_capability()', which performs capability checks on a user identity derived from the attacker-controlled 'original_user_id' cookie rather than validating the identity of the user currently authenticated via the WordPress session.\nSpecifically, the plugin erroneously utilizes the user ID provided in the cookie to verify administrative permissions. Instead of utilizing 'current_user_can()' to evaluate the privileges of the active session holder, the code implicitly trusts the cookie value as the target identity for the 'manage_options' capability check.\nThe attack flow proceeds as follows: First, an unauthenticated attacker sets the 'original_user_id' cookie in their HTTP request to match the user ID of a known administrator. Second, the plugin renders a switch-back form containing a session-bound nonce within the 'wp_footer' of the page. Crucially, the plugin emits this nonce to all visitors, including unauthenticated users, as long as the 'original_user_id' cookie is present.\nThird, the attacker extracts this valid, session-bound nonce from the HTML source. Finally, the attacker transmits a POST request to the 'revert_switch' handler, including the manipulated 'original_user_id' cookie and the harvested nonce. Upon receiving this request, the 'revert_switch' handler validates the nonce and, due to the flawed capability check, proceeds to invoke 'wp_set_auth_cookie()' using the administrator's ID specified in the cookie.\nThis execution path successfully bypasses standard WordPress authentication mechanisms, logging the attacker into the site with full administrative privileges. Because the 'revert_switch' handler acts as an unauthorized privilege escalation point, an attacker can gain persistent, high-privileged access, leading to arbitrary code execution, site defacement, or exfiltration of sensitive database content. This exploit is entirely network-exposed and requires no interaction from the administrator once the malicious request is crafted, making it a high-utility vector for mass exploitation in automated attacks against WordPress installations running the affected versions."
}