CVE-2026-14378 - DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow
CVE ID :CVE-2026-14378 Published : Oct. 2, 2026, 4:18 a.m. | 1 hour, 2 minutes ago Description :The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch`...