Mmastodon TechnologyCybersecurity first seen 10 h ago, last 10 h ago, peak #9
Critical authentication flaw disclosed in dplugins DevKit Pro
Original: CVE-2026-14378 | CRITICAL vuln in dplugins DevKit Pro ( https:// radar.offseq.com/threat/cve-20 26-14378-cwe-287-imprope
A critical vulnerability, tracked as CVE-2026-14378, has been disclosed in DevKit Pro, a plugin product by dplugins for WordPress. The flaw is classified as CWE-287, improper authentication, meaning the plugin may fail to correctly verify user identity, potentially letting attackers gain unauthorized access to sites running it. Security trackers are flagging it as critical, and WordPress administrators are being urged to check whether they use the affected plugin and apply fixes or mitigations.
Why now: Security communities are amplifying a newly disclosed critical WordPress plugin vulnerability that could expose sites to unauthorized access.
dpluginsDevKit ProWordPressCVE-2026-14378OffSeq
Evidence
- CVE-2026-14378 | CRITICAL vuln in dplugins DevKit Pro ( https:// radar.offseq.com/threat/cve-20 26-14378-cwe-287-improper-authentication-in-dplugins-devkit-pro-45d2af96cf344d90 # OffSeq # WordPress # Vuln # Infosec · offseq@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/692540