The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the revert_switch handler trusting the attacker-controlled original_user_id cookie as the privileged identity: verify_nonce_and_capability() incorrectly checks the manage_options capability on the user identified by the cookie rather than on the actual requester via current_user_can(), while the switch-back form and a valid session-bound nonce are emitted publicly via wp_footer to any visitor — including unauthenticated users — whenever that cookie is present. This makes it possible for unauthenticated attackers to set the original_user_id cookie to any administrator's user ID, collect the rendered nonce, and POST it back to the revert_switch handler, causing wp_set_auth_cookie() to be called with the administrator's ID and granting the attacker a full administrator-level authenticated session and complete site takeover.