Hackers exploit Modular DS WordPress plugin flaw for admin access
ID: 0d04f67e-eb43-5ace-b01b-0d6399ab3167
STIX ID: report--0d04f67e-eb43-5ace-b01b-0d6399ab3167
Feed Name: Bleeping Computer
Threat Score
A critical authentication-bypass vulnerability (CVE-2026-23550) in the Modular DS WordPress plugin (≤ 2.5.1, ~40k installs) is being actively exploited to gain admin-level access; the vendor released a patch in version 2.5.2 and recommends immediate updates, log review, checking for rogue admin accounts, and regenerating WordPress salts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
