← WordPress Vulnerabilities
WordPress security by component

DevKit Pro

DevKit Pro (devkit-pro) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 02, 2026; the highest published CVSS base score is 8.8.

Plugin slug: devkit-pro

CVE-2026-14357: DevKit Pro permits Subscriber-level arbitrary theme installation

DevKit Pro through 2.3.0 registers DPDEV_install_themes_func() on wp_ajax_DPDEV_install_themes without a capability check or nonce validation. A Subscriber or higher can install an arbitrary theme ZIP containing PHP into the web-accessible wp-content/themes directory, potentially leading to remote code execution.

PublishedSep 02, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for devkit-pro
Safe version
Sep 02, 2026 CVE-2026-14357
DevKit Pro permits Subscriber-level arbitrary theme installation
DevKit Pro through 2.3.0 registers DPDEV_install_themes_func() on wp_ajax_DPDEV_install_themes without a capability check or nonce validation. A Subscriber or higher can install an arbitrary theme ZIP containing PHP into the web-accessible wp-content/themes directory, potentially leading to remote code execution.
See mitigation notes
CVE8.8
NVDPending