CVE-2026-14378 is an authentication-bypass vulnerability affecting the DevKit Pro WordPress plugin through version 2.3.0. The revert_switch handler trusts the attacker-controlled original_user_id cookie as the identity to restore. Its verify_nonce_and_capability() function checks the manage_options capability of the cookie-selected user rather than the actual requester through current_user_can(). When the cookie is present, wp_footer publicly renders the switch-back form and a valid session-bound nonce, including for unauthenticated visitors. An attacker can select an administrator's user ID, retrieve the nonce, and submit it to the handler, causing wp_set_auth_cookie() to establish an administrator-level session and enabling complete site takeover.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This four-file Python repository contains a standalone proof-of-concept scanner and exploit helper for CVE-2026-14378 in dplugins DevKit Pro through version 2.3.0. Its main executable, poc.py, uses requests with TLS certificate verification disabled, normalizes supplied target URLs, follows redirects, and falls back between HTTP and HTTPS. It fingerprints likely plugin paths, then sends a forged original_user_id cookie to public WordPress pages and parses returned footer content for a user-switch revert nonce. Check mode performs this oracle/fingerprinting process without requesting the session-changing AJAX action. Admin mode posts the extracted nonce to WordPress admin-ajax.php using revert_switch and several possible DevKit action aliases, then checks for wordpress_logged_in_* cookies and /wp-admin/ access. It can try a configured user ID or a range, append successful targets to a log, and mass-process a file of targets with 50 workers. README.md documents the vulnerability, attack flow, invocation, expected indicators, and remediation; requirements.txt declares requests>=2.28.0; LICENSE is MIT. The code is an active exploitation utility rather than merely a detector, although it also offers a non-mutating check mode.
This 18-file standalone Python repository contains an active scanner and exploitation toolkit for the claimed CVE-2026-14378 in the DevKit Pro WordPress plugin. The main CLI, scan.py, parses individual or file-based targets and invokes a threaded Engine. core/probe.py implements version discovery through public plugin readmes, active verification by setting original_user_id=1 and parsing a leaked WordPress nonce, and an exploit path that posts the revert_switch action to obtain an administrator session. It then attempts persistent takeover by creating a randomized rogue administrator account. live_test.py and prove_takeover.py are local-lab proof scripts; notably, prove_takeover.py includes fixed rogue credentials and validates dashboard access, user enumeration, and user creation. A separate Nuclei-compatible YAML template provides detection only, but the primary tooling is not a framework module. publish_to_github.py is unrelated to exploitation and automates GitHub repository creation/pushing via the GitHub API and local git. The repository is operational exploit code rather than merely a detection utility because its --exploit mode performs authentication bypass and account creation.
This four-file Python repository contains an operational proof-of-concept for CVE-2026-14378, an unauthenticated administrator-session takeover in dplugins DevKit Pro versions up to 2.3.0. The principal code file, poc.py, uses requests with TLS certificate verification disabled, randomized browser-like headers, redirects enabled, and HTTP/HTTPS fallback. It fingerprints likely plugin installations through several exposed readme or PHP paths, then sets the attacker-controlled original_user_id cookie and requests public WordPress pages to detect a leaked user-switch revert nonce in wp_footer. In admin mode it submits the extracted nonce to /wp-admin/admin-ajax.php using revert_switch and three plausible plugin-specific action aliases, seeking a wordpress_logged_in_* cookie and validating access through /wp-admin/. The script supports detection-only checks, selected user IDs, sequential user-ID brute forcing, result logging, and threaded mass scanning of URL lists (default 50 workers). README.md documents the vulnerability, usage, mitigations, and expected behavior; requirements.txt declares requests>=2.28.0; LICENSE is MIT. This is standalone code rather than a recognized exploit framework module.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.