Actively exploited critical flaw in Modular DS WordPress plugin enables admin takeover
ID: 36893b32-122d-58e8-84c6-4c7c60a6fcd8
STIX ID: report--36893b32-122d-58e8-84c6-4c7c60a6fcd8
Feed Name: Security Affairs
Threat Score
**Executive summary:** A critical vulnerability (CVE-2026-23550, CVSS 10) in the Modular DS WordPress plugin (≤2.5.1, ~40k installs) allows unauthenticated privilege escalation and automatic admin login via a flawed direct-request check; active exploitation began on 2026-01-13 targeting the plugin login API (observed attacker IPs: 45.11.89.19, 185.196.0.11), and the issue is fixed in v2.5.2 — site owners should update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
