Skip to content

CVE-2026-23550

CVE

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
January 15, 2026
Last Seen
March 5, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical vulnerability (CVE-2026-1492) in the User Registration & Membership plugin, used by over 60,000 WordPress sites, is being actively exploited by hackers to create unauthorized admin accounts. The vulnerability has a severity rating of 9.8, indicating a significant risk to affected sites, w...

A critical security flaw (CVE-2026-23550) in the Modular DS WordPress plugin has been identified, allowing attackers to bypass admin controls. Discovered by Patchstack, the vulnerability has a severity score of 10/10 and is actively being exploited, affecting approximately 40,000 websites.

A privilege escalation vulnerability in the Modular DS WordPress plugin, tracked as CVE-2026-23550, has been actively exploited by hackers to gain full admin access to vulnerable sites. This flaw affects versions 2.5.1 and older of the plugin, which is widely used for managing multiple WordPress sit...

Public Exploits

Checking GitHub for proof-of-concept code…