Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
A critical vulnerability (CVE-2026-1492) in the User Registration & Membership plugin, used by over 60,000 WordPress sites, is being actively exploited by hackers to create unauthorized admin accounts. The vulnerability has a severity rating of 9.8, indicating a significant risk to affected sites, w...
A critical security flaw (CVE-2026-23550) in the Modular DS WordPress plugin has been identified, allowing attackers to bypass admin controls. Discovered by Patchstack, the vulnerability has a severity score of 10/10 and is actively being exploited, affecting approximately 40,000 websites.
A privilege escalation vulnerability in the Modular DS WordPress plugin, tracked as CVE-2026-23550, has been actively exploited by hackers to gain full admin access to vulnerable sites. This flaw affects versions 2.5.1 and older of the plugin, which is widely used for managing multiple WordPress sit...