Vulnerability Management, Identity, Patch/Configuration Management

Modular DS WordPress plugin vulnerability allows admin access

(Credit: Bilal Ulker – stock.adobe.com)

Hackers are actively exploiting a critical vulnerability in the Modular DS WordPress plugin, enabling them to bypass authentication and gain administrative privileges on affected sites. The flaw, identified as CVE-2026-23550, impacts versions 2.5.1 and older of the plugin, which is used by over 40,000 installations for managing multiple WordPress sites remotely. This vulnerability allows unauthenticated attackers to achieve immediate privilege escalation, as reported by Bleeping Computer.

The vulnerability stems from flaws in the plugin's handling of "direct request" mode, where it accepted requests without proper cryptographic verification. This allowed access to sensitive routes and triggered an automatic admin login fallback. If no user ID was provided, the plugin would log in as an existing administrator. Researchers at Patchstack detected the first attacks on January 13. Modular DS released version 2.5.2 with a fix shortly after, addressing the route matching and adding a safe failure mode for unrecognized requests.

The rapid exploitation and patching of this vulnerability highlight the ongoing threat landscape for WordPress users. The vendor recommends updating to version 2.5.2 immediately, reviewing server logs for suspicious activity, checking for unauthorized admin users, and regenerating WordPress salts.

Source: Bleeping Computer

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds