CVE-2026-14378

CVE-2026-14378 published: The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` c...

View full NVD advisory → ← Back to CVE watch