CVE Record
[ CRITICAL ]CVE-2026-14378
DevKit Pro Auth Bypass via Unsecured Action Hook Enables Admin Takeover
DevKit Pro through 2.3.0 has an authentication bypass via an unsecured WordPress action hook, exposing administrator account takeover to unauthenticated attackers.
- Vendor
- dPlugins
- Product
- DevKit Pro WordPress Plugin (versions up to and including 2.3.0)
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.5%
- Status
- patched
- Published
CVE-2026-14378 is a CVSS 9.8 critical authentication bypass in the DevKit Pro WordPress plugin, affecting all versions up to and including 2.3.0. The revert_switch handler is hooked to a WordPress action without adequate authentication verification, allowing an unauthenticated attacker to trigger administrator account takeover.
Site administrators should update through the WordPress admin dashboard. Deactivation is the recommended interim measure if an immediate update is not possible.
Source: NVD.