WPHizmet

Eklenti güvenlik geçmişi

DevKit Pro güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) DevKit Pro eklentisi için 2 açık kaydı bulunuyor; en yenisi 2 Ekim 2026 tarihli. Bunların 2 tanesi kritik veya yüksek önemde, 1 tanesi oturum açmadan istismar edilebiliyor.

Toplam kayıt
2
Kritik veya yüksek
2
Oturumsuz istismar
1
Son kayıt
2 Ekim 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-14378Kritik · 9,82 Ekim 2026

    kimlik doğrulama atlatma

    Etkilenen sürümler: 2.3.0 ve öncesi · Oturum açmadan istismar edilebilir

    The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by the cookie rather than on the actual requester via `current_user_can()`, while the switch-back form and a valid session-bound nonce are emitted publicly via `wp_footer` to any visitor — including unauthenticated users — whenever that cookie is present. This makes it possible for unauthenticated attackers to set the `original_user_id` cookie to any administrator's user ID, collect the rendered nonce, and POST it back to the `revert_switch` handler, causing `wp_set_auth_cookie()` to be called with the administrator's ID and granting the attacker a full administrator-level authenticated session and complete site takeover.

    Türkçe kayıt ve ne yapmalı
  • CVE-2026-14357Yüksek · 8,82 Eylül 2026

    uzaktan kod çalıştırma

    Etkilenen sürümler: 2.3.0 ve öncesi

    The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registered on the wp_ajax_DPDEV_install_themes action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary theme ZIP packages containing PHP files that are extracted into the web-accessible wp-content/themes/ directory, which may make remote code execution possible.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.