MBSD-SOC reported a rise in March attack activity targeting CVE-2026-23550, a critical authentication-bypass vulnerability in the Modular DS WordPress plugin. The flaw affects versions 2.5.1 and earlier and can allow unauthenticated attackers to gain administrator privileges; it has been assigned a CVSS 10.0 severity rating in the CVE record.
Observed exploit attempts abused requests to the plugin's modular-connector login API, including parameters such as origin=mo and type, in an apparent effort to bypass authentication. MBSD-SOC said many of the attack sources seen during the surge were located in the United States and the United Kingdom, and urged organizations running the plugin to upgrade immediately to version 2.5.2 or later.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
MBSD-SOC reported an increase in attacks during March 2026 targeting CVE-2026-23550 in the Modular DS WordPress plugin. The observed exploit traffic attempted authentication bypass via the modular-connector login API using parameters such as "origin=mo" and "type".
MBSD-SOC reported that it had tracked detections of attacks targeting CVE-2026-23550 from February 2026 onward. In February, observed attack-source countries included Germany, Japan, the United States, Australia, and Egypt.
CVE-2026-23550 was publicly disclosed on January 14, 2026. The flaw affects Modular DS WordPress plugin versions 2.5.1 and earlier and can allow unauthenticated attackers to obtain administrator privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.