HomeSecurityModular DS: Critical vulnerability in WordPress plugin

Modular DS: Critical vulnerability in WordPress plugin

A serious security threat to thousands of WordPress is currently underway, as a critical vulnerability in the popular Modular DS. According to cybersecurity firm Patchstack, the issue allows unauthorized attackers to gain administrator privileges, potentially leading to a complete compromise of a site.

Modular DS

What is CVE-2026-23550 and why is it considered extremely dangerous?

The vulnerability has been recorded as CVE-2026-23550 (CVSS 10.0). It affects all versions of Modular DS up to 2.5.1, and has been fixed in version 2.5.2. The fact that the plugin has more than 40,000 active installations makes the risk particularly widespread.

See also: AWS CodeBuild: Misconfiguration put GitHub repos at risk

Essentially, this is an unauthorized privilege escalation, which allows third parties to bypass authentication mechanisms and automatically log in as administrators.

How bypassing security mechanisms works

The root of the problem lies in the Modular DS routing system. The plugin exposes critical API routes under the/api/modular-connector/, which are theoretically protected from authentication. However, enabling the “direct request” feature allows these checks to be bypassed. Specifically, by sending a request that includes parameters such as origin=mo and type with any value, the system treats the request as a trusted internal request. As long as the site has connected even once to Modular, there is no cryptographic verification linking the request to the legitimate service.

Modular DS: Critical vulnerability in WordPress plugin

Which paths are exposed and what an attacker can do

The vulnerability exposes routes such as /login/, /server-information/, /manager/, and /backup/. Through these, an attacker could obtain system information, user data, or even connect remotely.

See also: Windows Remote Assistance: Vulnerability allows MOTW bypass

The most worrying scenario concerns the /login/{modular_request} path, through which it is possible to gain immediate administrator access. From there, the path to installing malicious code, corrupting content, or redirecting visitors to scams is open.

Active attacks and technical details

The first attacks were recorded on January 13, 2026, at approximately 02:00 UTC. HTTP GET requests to the endpoint /api/modular-connector/login/ were observed, followed by attempts to create new users with administrator privileges. The attacks are reported to have originated from, among others, theIP addresses 45.11.89[.]19 and 185.196.0[.]11.

Modular DS: Critical vulnerability in WordPress plugin

Modular DS: What WordPress admins should do immediately

Due to the active exploit, Modular DS users are urged to upgrade to version 2.5.2 immediately. In addition, it is recommended to check for signs of compromise, such as unknown administrators or suspicious activity.

The basic recovery steps include:

  • Regenerating WordPress salts to cancel all sessions
  • Regenerate OAuth credentials
  • Full site scan for malicious plugins or files

See also: Vulnerability in Microsoft SQL Server allows elevation of privilege

A lesson in security design

As both Patchstack and the plugin maintainers point out, the vulnerability is not due to a single bug, but rather a combination of overly permissive design choices. The incident highlights how dangerous implicit trust in internal paths can be when they are exposed to the public internet — a lesson with broader implications for the entire WordPress ecosystem.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS