A critical unauthenticated privilege-escalation vulnerability in the Modular DS WordPress plugin is being actively exploited in the wild to obtain administrator access. The flaw, tracked as CVE-2026-23550 (CVSS 10.0), affects all versions up to and including 2.5.1 and is fixed in 2.5.2; the plugin is reported to have 40,000+ active installs. The issue stems from the plugin’s routing/authentication design under the /api/modular-connector/ prefix, where attackers can bypass authentication middleware by forcing “direct request” handling using parameters such as origin=mo and an arbitrary type value, particularly when the site is already connected to Modular services (i.e., tokens are present/renewable).
Exploitation leverages exposed routes including /login/ (notably /api/modular-connector/login/ / /login/{modular_request}), enabling auto-login behavior that results in administrator-level access and potential full site compromise (e.g., data access, backups, management actions, and follow-on malware/persistence). Reporting also notes observed attacker behavior and indicators tied to exploitation attempts against the login endpoint (e.g., requests containing origin=mo&type=foo) and lists IPs associated with scanning and post-exploitation activity, including 45.11.89[.]19, 162.158.123[.]41, 172.70.176[.]95, and 172.70.176[.]52. Patch guidance emphasizes immediate upgrade to 2.5.2, and mitigations include rules intended to block exploit patterns and hardening changes such as stricter route binding and type validation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
By 2026-01-19, follow-on reporting described continued opportunistic exploitation of vulnerable Modular DS installations, including web shell deployment, malicious plugin installation, phishing or malware content changes, and possible data theft. The reporting also noted that public proof-of-concept details were helping accelerate compromise attempts.
Following notification and disclosure on 2026-01-14, the vendor released Modular DS version 2.5.2 to remediate the flaw. The fix changed route handling for the affected subsystem and added safer defaults for unrecognized requests to prevent the auth bypass path.
On 2026-01-14, Patchstack publicly disclosed a critical unauthenticated privilege-escalation vulnerability in Modular DS affecting versions 2.5.1 and earlier, impacting more than 40,000 sites. The advisory described the authentication bypass chain, assigned CVE-2026-23550, and released a mitigation rule plus indicators and response guidance for defenders.
Patchstack observed the first exploitation attempts against the Modular DS WordPress plugin on 2026-01-13 around 02:00 UTC. Attackers abused the unauthenticated privilege-escalation flaw later tracked as CVE-2026-23550 to access admin functionality and attempt creation of rogue administrator accounts such as "PoC Admin."
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
rescana.com
Open sourcescworld.com
Open sourcecsoonline.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcepatchstack.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.