logo

002

ID: f1d35f9e-9c5c-4091-9249-d2f0fd6f4903

STIX ID: report--f1d35f9e-9c5c-4091-9249-d2f0fd6f4903

Threat Score

85/100

Uploaded: 2026-05-14

Published Date: 2026-05-14

Last Modified Date: 2026-05-14

Created by: Thesis Research

TLP:GREEN
...
...
A critical unauthenticated privilege-escalation flaw (CVE-2026-23550, CVSS 10.0) in the Modular DS WordPress plugin (<=2.5.1, ~40k installs) has been actively exploited to obtain administrator access via the /api/modular-connector/ endpoints when 'direct request' mode and crafted origin/type parameters are used; attacks were observed on Jan 13, 2026 with IP indicators and users are urged to update to 2.5.2 and scan for compromise.