Bleepingcomputer
Critical Flaw in Modular DS Plugin Allows Unauthorized WordPress Admin Access
First seen 16 Jan 2026, 16:54 UTC
•



•86% similarity
•33.4
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A privilege escalation vulnerability in the Modular DS WordPress plugin, tracked as CVE-2026-23550, has been actively exploited by hackers to gain full admin access to vulnerable sites. This flaw affects versions 2.5.1 and older of the plugin, which is widely used for managing multiple WordPress sites. Security researchers have confirmed the severity of this issue, assigning it a CVSS score of 10.0.
ThreatCluster AI
How this analysis works