Critical Flaw in Modular DS Plugin Allows Unauthorized WordPress Admin Access

Critical Flaw in Modular DS Plugin Allows Unauthorized WordPress Admin Access

First seen 16 Jan 2026, 16:54 UTC BleepingcomputerCsoonlineRedhotcyberRescanaHeise.De 86% similarity 33.4

Article Content

Browse articles
ThreatCluster

A privilege escalation vulnerability in the Modular DS WordPress plugin, tracked as CVE-2026-23550, has been actively exploited by hackers to gain full admin access to vulnerable sites. This flaw affects versions 2.5.1 and older of the plugin, which is widely used for managing multiple WordPress sites. Security researchers have confirmed the severity of this issue, assigning it a CVSS score of 10.0.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story