logo

Actively exploited critical flaw in Modular DS WordPress plugin enables admin takeover

ID: 36893b32-122d-58e8-84c6-4c7c60a6fcd8

STIX ID: report--36893b32-122d-58e8-84c6-4c7c60a6fcd8

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-01-16

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

**Executive summary:** A critical vulnerability (CVE-2026-23550, CVSS 10) in the Modular DS WordPress plugin (≤2.5.1, ~40k installs) allows unauthenticated privilege escalation and automatic admin login via a flawed direct-request check; active exploitation began on 2026-01-13 targeting the plugin login API (observed attacker IPs: 45.11.89.19, 185.196.0.11), and the issue is fixed in v2.5.2 — site owners should update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.