216.73.216.6

Critical Privilege Escalation Vulnerability in Modular DS plugin affecting 40k+ Sites exploited in the wild

· Published 20/01/2026 17:02 · Modified 20/01/2026 19:15

Export JSON

Essential information

Published
20/01/2026 17:02
Modified
20/01/2026 19:15
Tags
2026-01-20 CVE-2026-23550 CVE-2026-23800 active exploitation modular ds plugin vulnerability privilege-escalation unauthenticated wordpress
Related entities
3 observables, 5 techniques (mitre)

Description

A critical privilege escalation vulnerability has been discovered in the plugin, affecting over 40,000 sites. The flaw allows attackers to bypass authentication and gain admin access. Exploitation attempts have been observed in the wild, with attackers creating unauthorized admin accounts. The vulnerability stems from flawed route handling and authentication mechanisms. Patchstack has issued mitigation rules and assigned . The plugin developer has released version 2.6.0 to address the issue. Users are urged to update immediately. Additional exploit paths were later discovered, leading to the assignment of . The vulnerability highlights the dangers of implicit trust in internal request paths when exposed to the public internet.

External references