DEV Community

threataft
threataft

Posted on Originally published at threataft.com

WordPress Auth Bypass Cluster — 4 CVSS 9.8, Full Site Takeover via Plugin Flaws

Four WordPress plugins dropped CVSS 9.8 authentication bypass vulnerabilities on the same day. All four let unauthenticated attackers take over administrator accounts with no credentials required.

Affected plugins:

DevKit Pro ≤ 2.3.0 — cookie-based admin takeover via revert_switch (CVE-2026-14378)
Divi Membership ≤ 2.3.0 — unauthenticated login via paypal_param GET parameter (CVE-2026-19660)
JSON API Auth ≤ 3.1.2 — cached admin session cookie served to unauthenticated requests (CVE-2026-97637)
WPMobile.App ≤ 11.82 — password-reset URLs exposed via push queue (CVE-2026-94541)

Wordfence blocked 137 attacks targeting WPMobile.App in 24 hours. Public PoC with mass-scan capability exists for DevKit Pro.

Fixed versions: DevKit Pro 2.3.1, Divi Membership 3.0.0, JSON API Auth 3.1.3, WPMobile.App 11.85.

Full technical breakdown on ThreatAft →

Top comments (0)