Skip to content
feed: live
>_0dayNews
wordpress
Analysis

Four WordPress Plugins at CVSS 9.8: Auth Bypass Persists

Four critical authentication bypass flaws in WordPress plugins this week affect a mobile app builder, a JSON auth module, a developer toolkit, and a membership system.

kilobaudDave "Kilobaud" Ferris·Published ·1 min read

Four WordPress plugins disclosed authentication bypass vulnerabilities this week, each at CVSS 9.8 critical. The vulnerability class is the same across all four: an unauthenticated attacker gains access to privileged functionality without valid credentials.

The affected plugins:

  • WPMobile.App (CVE-2026-94541, CVSS 9.8): an authorization bypass in the plugin’s push notification API endpoint, affecting all versions up to and including 11.82
  • JSON API Auth (CVE-2026-97637, CVSS 9.8): a cached session cookie disclosure flaw that allows an unauthenticated user to authenticate as any existing account, affecting all versions up to and including 3.1.2
  • DevKit Pro (CVE-2026-14378, CVSS 9.8): an authentication bypass through an improperly secured WordPress action hook that exposes administrator account takeover, affecting all versions up to and including 2.3.0
  • Divi Membership (CVE-2026-19660, CVSS 9.8): an authentication bypass in the plugin’s PayPal callback function, hooked to the WordPress init action without adequate verification of the caller, affecting all versions up to and including 2.3.0

Patches are available for all four. Site operators should update through the WordPress admin dashboard. Where an immediate update isn’t possible, deactivating the plugin is the safer interim step.

Authentication bypass in WordPress plugin code tends to cluster around familiar problem areas: REST API endpoints that skip permission checks, hooks registered before authentication context is established, and session handling that over-trusts client-supplied values. Each pattern appears somewhere in this week’s set.

Four at CVSS 9.8 from different vendors in a single week is not historically unprecedented in the WordPress ecosystem, but it’s a useful prompt to audit which plugins are active on any given site, and whether each one is kept current. Unused plugins running outdated code are the version of this problem that tends to actually get sites compromised.

For cross-reference: Critical File Upload Bug in WooCommerce Quote Plugin, WordPress Core RCE Flaw CVE-2026-87902 Under Active Exploit, CVSS 10 Flaw in WordPress Payment Plugin Grants Admin Access, Events Calendar Plugin: Two CVSS 9.8 RCEs.

Related CVEs
  • [ CRITICAL ]CVE-2026-94541WPMobile.App Authorization Bypass in Push Notification API
  • [ CRITICAL ]CVE-2026-97637JSON API Auth Cached Session Cookie Disclosure Allows Auth Bypass
  • [ CRITICAL ]CVE-2026-14378DevKit Pro Auth Bypass via Unsecured Action Hook Enables Admin Takeover
  • [ CRITICAL ]CVE-2026-19660Divi Membership Auth Bypass via PayPal Callback Hook

Found this useful? Share it.