002
ID: f1d35f9e-9c5c-4091-9249-d2f0fd6f4903
STIX ID: report--f1d35f9e-9c5c-4091-9249-d2f0fd6f4903
Threat Score
85/100
Uploaded: 2026-05-14
Published Date: 2026-05-14
Last Modified Date: 2026-05-14
Created by: Thesis Research
TLP:GREEN
...
...
A critical unauthenticated privilege-escalation flaw (CVE-2026-23550, CVSS 10.0) in the Modular DS WordPress plugin (<=2.5.1, ~40k installs) has been actively exploited to obtain administrator access via the /api/modular-connector/ endpoints when 'direct request' mode and crafted origin/type parameters are used; attacks were observed on Jan 13, 2026 with IP indicators and users are urged to update to 2.5.2 and scan for compromise.
