Four WordPress plugins dropped CVSS 9.8 authentication bypass vulnerabilities on the same day. All four let unauthenticated attackers take over administrator accounts with no credentials required.
Affected plugins:
DevKit Pro ≤ 2.3.0 — cookie-based admin takeover via revert_switch (CVE-2026-14378)
Divi Membership ≤ 2.3.0 — unauthenticated login via paypal_param GET parameter (CVE-2026-19660)
JSON API Auth ≤ 3.1.2 — cached admin session cookie served to unauthenticated requests (CVE-2026-97637)
WPMobile.App ≤ 11.82 — password-reset URLs exposed via push queue (CVE-2026-94541)
Wordfence blocked 137 attacks targeting WPMobile.App in 24 hours. Public PoC with mass-scan capability exists for DevKit Pro.
Fixed versions: DevKit Pro 2.3.1, Divi Membership 3.0.0, JSON API Auth 3.1.3, WPMobile.App 11.85.
Full technical breakdown on ThreatAft →
Top comments (0)