Four WordPress plugins hit by CVSS 9.8 auth bypass flaws
Four WordPress plugins were found to have CVSS 9.8 authentication bypass vulnerabilities on the same day, letting unauthenticated attackers take over administrator accounts without credentials. Wordfence blocked 137 attacks on WPMobile.App in 24 hours; patched versions are available.
- DevKit Pro ≤ 2.3.0: cookie-based admin takeover via revert_switch (CVE-2026-14378)
- Divi Membership ≤ 2.3.0: unauthenticated login via paypal_param parameter (CVE-2026-19660)
- JSON API Auth ≤ 3.1.2 served cached admin session cookies to anonymous requests (CVE-2026-97637)
- Fixes: DevKit Pro 2.3.1, Divi Membership 3.0.0, JSON API Auth 3.1.3, WPMobile.App 11.85
Read next
Security