Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-14378

DevKit Pro Auth Bypass via Unsecured Action Hook Enables Admin Takeover

DevKit Pro through 2.3.0 has an authentication bypass via an unsecured WordPress action hook, exposing administrator account takeover to unauthenticated attackers.

cat cve-2026-14378.json
Vendor
dPlugins
Product
DevKit Pro WordPress Plugin (versions up to and including 2.3.0)
CVSS
9.8
EPSS (exploit probability)
0.5%
Status
patched
Published

CVE-2026-14378 is a CVSS 9.8 critical authentication bypass in the DevKit Pro WordPress plugin, affecting all versions up to and including 2.3.0. The revert_switch handler is hooked to a WordPress action without adequate authentication verification, allowing an unauthenticated attacker to trigger administrator account takeover.

Site administrators should update through the WordPress admin dashboard. Deactivation is the recommended interim measure if an immediate update is not possible.

Source: NVD.