ThreatCluster

Critical WordPress Plugin Flaw Exposes 40,000 Websites to Attack

First seen 16 Jan 2026, 15:10 UTC CyberpressCybersecuritynewsTechradarMsnWordfence+1 78% similarity 36

Article Content

Browse articles
ThreatCluster

A critical security flaw (CVE-2026-23550) in the Modular DS WordPress plugin has been identified, allowing attackers to bypass admin controls. Discovered by Patchstack, the vulnerability has a severity score of 10/10 and is actively being exploited, affecting approximately 40,000 websites.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story