logo

Exploited in the Wild: Critical Modular DS Flaw CVE-2026-23550 (CVSS 10) Allows Instant Admin Takeover

ID: 28589d91-841b-529a-b4ce-5f94f5e99130

STIX ID: report--28589d91-841b-529a-b4ce-5f94f5e99130

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-01-15

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical CVE-2026-23550 privilege escalation in the Modular DS WordPress plugin (≤2.5.1) enables unauthenticated attackers to bypass authentication by supplying ?origin=mo (and type), permitting administrative account creation and backdoor installation; active exploitation targeting ~40,000 sites was observed from January 13 onward, IOCs (e.g., 45.11.89.19, 162.158.123.41) are reported, and the vendor has released a patch that refactors routing/auth checks to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.