CVE-2026-23550Active Exploitation

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1.

6.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

RISING

Threat summary

  • Active exploitation appears in 6 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 8 observed days

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 9 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-05-13); latest day: 2
  • 12 total mentions across 8 days

Deep dive

Activity timeline12 mentions / 8d
01223Mentions · 2026-01-28: 2Mentions · 2026-01-29: 1Mentions · 2026-02-17: 1Mentions · 2026-02-25: 1Mentions · 2026-03-23: 1Mentions · 2026-05-13: 3Mentions · 2026-08-02: 1Mentions · 2026-10-09: 2Exploit Tool / Code · 2026-02-25: 1Active Exploitation · 2026-01-28: 2Active Exploitation · 2026-01-29: 1Active Exploitation · 2026-02-25: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-05-13: 1Patch / Workaround · 2026-01-28: 2Patch / Workaround · 2026-08-02: 1Technical Details · 2026-01-28: 2Technical Details · 2026-01-29: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-25: 1Technical Details · 2026-03-23: 1Technical Details · 2026-05-13: 2Technical Details · 2026-08-02: 101-2801-2902-1702-2503-2305-1308-0210-09
Signal classification4 categories
Active Exploitation
660.0%
Disclosure
220.0%
General
110.0%
Patch
110.0%
Referenced assets32 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-282
Active Exploitation2
2026-01-291
Active Exploitation1
2026-02-171
Disclosure1
2026-02-251
Active Exploitation1
2026-03-231
Active Exploitation1
2026-05-133
Active Exploitation1Disclosure1General1
2026-08-021
Patch1
Full discourse12 posts
  • モーくん🐮|WordPress × セキュリティ@accell_mo_kun
    Patch

    おはモー🐮 WPプラグインModular DS、ログイン不要で管理者権限まで取れる穴が出たモー🐮 開示から今日で185日、修正版2.5.2は公開済みモー🐄 半年放置の理由は自分の手元にしかない、今日プラグイン一覧を数えるモー🐮 #おは戦80803ag🌛 #Webセキュリティ https://security.berkeley.edu/news/cve-2026-23550-wordpress-modular-ds-flaw

    Post summary

    The WP plugin Modular DS contains a flaw that lets attackers gain administrator rights without needing to log in, and the newly released patch version 2.5.2 is now available.

    010130143
    913 followersView on X
  • ♫NØX♥H♪@_Why_Noot

    NØX Echo Lineage Signal: CVE-2026-23550 Entity: WordPress Modular DS Plugin Lineage: Public vulnerability → Public exploit/PoC → Observed exploitation Relationship: - WordPress Modular DS Plugin → CVE-2026-23550 → Evidence → Operational Risk Current State:

    1000021
    8 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Next-Gen Supply Chain Poisoning: CVE-2026-23550 WordPress Plugin Attack and How LLM-Based Intent Analysis Caught It. A poisoned auto-update to a popular WordPress plugin nearly exfiltrated admin credentials from 50,000+ sites.

    Post summary

    CVE-2026-23550 exposed a supply‑chain poisoning flaw in a WordPress plugin, resulting in the exfiltration of admin credentials from over 50,000 sites, evidencing widespread active exploitation.

    1000046
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-23550 affected a WordPress plugin with 50,000+ active installations. A poisoned auto-update added a small, well-disguised payload to the plugin's existing analytics module — code that, on every admin page load, posted the WordPress salt keys plus the encrypted…

    Post summary

    CVE-2026-23550 is a WordPress plugin vulnerability whereby a malicious auto‑update injects a disguised payload that sends WordPress salt keys to an attacker.

    1000055
    210 followersView on X
  • Ben Ryan@BenRyanMe
    Active Exploitation

    February 2026. CVE-2026-23550 drops. CVSS 10.0 — maximum severity. 40,000+ WordPress sites running the Modular DS plugin are exposed. I manage 150+ client sites. Some were running it. Automated exploit attempts started before most agencies finished reading the advisory.

    Post summary

    CVE‑2026‑23550, rated CVSS 10.0, is already being exploited in the wild against WordPress Modular DS plugin installations, with automated attack attempts underway.

    1000038
    724 followersView on X
  • ProbablyPwned@probablypwned
    Active Exploitation

    "🚨 Critical Vulnerability Alert: CVE-2026-23550 in Modular DS plugin scores CVSS 10.0! Active exploitation began Jan 13, with 40,000+ sites at risk. Read more: https://www.probablypwned.com/article/wordpress-modular-ds-cve-2026-23550-admin-takeover

    Post summary

    The post alerts that CVE-2026-23550 is being actively exploited with a CVSS score of 10.0, affecting over 40,000 sites, and points to an article for further details.

    1000085
    16 followersView on X
  • @ByteVanguardSec@ByteVanguardSec
    Active Exploitation

    Active exploits! CVE-2026-23550 in Modular DS WordPress plugin = unauthenticated admin takeover on 40K+ sites. Patch to 2.5.2 NOW before your site is owned! Full details &amp; fix guide: https://bytevanguard.com/2026/01/28/wordpress-modular-ds-cve-2026-23550-unauthenticated-admin-takeover/ #WordPress #CyberSecurity #CVE202623550 #Vulnerability #PluginSecurity

    Post summary

    The post announces that CVE-2026-23550 is actively exploited for unauthenticated admin takeover on over 40,000 WordPress sites, urging users to patch to version 2.5.2 immediately.

    0001099
    3 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2026-23550 Product: Modular DS / WordPress Modular DS Plugin Summary: VulnCheck reports real-world exploitation activity affecting Modular DS / WordPress Modular DS Plugin. Evidence: Public PoC/exploit available; Active exploitation reported; Severe impact class; Live exploitation observed by VulnCheck canaries Impact: The vulnerability has a severe impact class such as code execution, authentication bypass, account takeover, or privilege escalation. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 14 Jan 2026 Source: https://vulncheck.com/xdb/c2e0dca19caa #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #WordPress_Modular_DS_Plugin #CVE_2026_23550 #ActiveExploitation #Exploit

    0000033
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-23550-wordpress-plugin-supply-chain-llm-intent-analysis #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text only contains a link to a research article on CVE‑2026‑23550, with no explicit details about PoC, exploitation, patches, technical specifics, or false positives.

    0000035
    210 followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #MediumCompleteness January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day | 24-02-2026 Source: https://www.recordedfuture.com/blog/january-2026-cve-landscape Key details below ↓ 🧑‍💻Actors/Campaigns: Fancy_bear Neusploit 💀Threats: Nuclei_tool, Minidoor, Pixynetloader, Covenant_c2_tool, Grunt, Com_hijacking_technique, Supply_chain_technique, 🎯Victims: Enterprise communication platforms, Enterprise management platforms, Government users, Business users, Wordpress sites, Email systems 🏭Industry: Government 🌐Geo: Russian 🔓CVEs: CVE-2026-23760 \[[Vulners](https://vulners.com/cve/CVE-2026-23760)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9511) CVE-2025-34026 \[[Vulners](https://vulners.com/cve/CVE-2025-34026)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - versa-networks concerto (<12.1.2, 12.2.0) CVE-2009-0556 \[[Vulners](https://vulners.com/cve/CVE-2009-0556)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - microsoft office_powerpoint (2004) - microsoft powerpoint (2000, 2002, 2003) CVE-2025-8110 \[[Vulners](https://vulners.com/cve/CVE-2025-8110)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - gogs (le0.13.3) CVE-2026-24423 \[[Vulners](https://vulners.com/cve/CVE-2026-24423)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9511) CVE-2025-68645 \[[Vulners](https://vulners.com/cve/CVE-2025-68645)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - synacor zimbra_collaboration_suite (<10.0.18, <10.1.13) CVE-2018-14634 \[[Vulners](https://vulners.com/cve/CVE-2018-14634)] - CVSS V3.1: *7.8*, - Vulners: Exploitation: True Soft: - paloaltonetworks pan-os (<7.1.23, <8.0.16, <8.1.7) CVE-2026-21509 \[[Vulners](https://vulners.com/cve/CVE-2026-21509)] - CVSS V3.1: *7.8*, - Vulners: Exploitation: True Soft: - microsoft 365_apps (-) - microsoft office (2016, 2019) - microsoft office_long_term_servicing_channel (2021, 2024) CVE-2025-37164 \[[Vulners](https://vulners.com/cve/CVE-2025-37164)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True Soft: - hpe oneview (le10.20.00) CVE-2026-1340 \[[Vulners](https://vulners.com/cve/CVE-2026-1340)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ivanti endpoint_manager_mobile (le12.7.0.0) CVE-2026-1281 \[[Vulners](https://vulners.com/cve/CVE-2026-1281)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ivanti endpoint_manager_mobile (le12.5.0.0, 12.5.1.0, 12.6.0.0, 12.6.1.0, 12.7.0.0) CVE-2026-20045 \[[Vulners](https://vulners.com/cve/CVE-2026-20045)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - cisco unified_communications_manager (<14su5, le15su3a) - cisco unified_communications_manager_im_and_presence_service (<14su5, le15su3a) - cisco unity_connection (<14su5, le15su3) CVE-2026-20931 \[[Vulners](https://vulners.com/cve/CVE-2026-20931)] - CVSS V3.1: *8.0*, - Vulners: Exploitation: Unknown Soft: - microsoft windows_10_1607 (<10.0.14393.8783) - microsoft windows_10_1809 (<10.0.17763.8276) - microsoft windows_10_21h2 (<10.0.19044.6809) - microsoft windows_10_22h2 (<10.0.19045.6809) ... CVE-2026-20805 \[[Vulners](https://vulners.com/cve/CVE-2026-20805)] - CVSS V3.1: *5.5*, - Vulners: Exploitation: True Soft: - microsoft windows_10_1607 (<10.0.14393.8783) - microsoft windows_10_1809 (<10.0.17763.8276) - microsoft windows_10_21h2 (<10.0.19044.6809) - microsoft windows_10_22h2 (<10.0.19045.6809) ... CVE-2025-52691 \[[Vulners](https://vulners.com/cve/CVE-2025-52691)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9413) CVE-2025-31125 \[[Vulners](https://vulners.com/cve/CVE-2025-31125)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - vitejs vite (<4.5.11, <5.4.16, <6.0.13, <6.1.3, <6.2.4) CVE-2026-24858 \[[Vulners](https://vulners.com/cve/CVE-2026-24858)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - fortinet fortianalyzer (le7.0.15, le7.2.11, <7.4.10, <7.6.6) - fortinet fortimanager (le7.0.15, le7.2.11, <7.4.10, <7.6.6) - fortinet fortiproxy (le7.0.22, le7.2.15, le7.4.12, le7.6.4) - fortinet fortiweb (le7.4.11, le7.6.6, le8.0.3) ... CVE-2025-54313 \[[Vulners](https://vulners.com/cve/CVE-2025-54313)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - prettier eslint-config-prettier (8.10.1, 9.1.1, 10.1.6, 10.1.7) CVE-2025-40551 \[[Vulners](https://vulners.com/cve/CVE-2025-40551)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - solarwinds web_help_desk (<2026.1) CVE-2026-20029 \[[Vulners](https://vulners.com/cve/CVE-2026-20029)] - CVSS V3.1: *4.9*, - Vulners: Exploitation: Unknown CVE-2026-23550 \[[Vulners](https://vulners.com/cve/CVE-2026-23550)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: Unknown CVE-2026-23800 \[[Vulners](https://vulners.com/cve/CVE-2026-23800)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: Unknown CVE-2024-37079 \[[Vulners](https://vulners.com/cve/CVE-2024-37079)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - vmware cloud_foundation (<5.2) CVE-2026-24061 \[[Vulners](https://vulners.com/cve/CVE-2026-24061)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - gnu inetutils (le2.7) 🤖LLM extracted TTPs:` T1005, T1027, T1053.005, T1071.001, T1078, T1090, T1098, T1112, T1114.003, T1133, ... 🧨IOCs: - Path: 2 - Registry: 1 - IP: 6 - Email: 4 - File: 2 💽Software: Microsoft Office, Ivanti, Linux, Zimbra Collaboration Suite, WordPress, Outlook, Ivanti EPMM 🔢Algorithms: xor 📜Programming Languages: php #threatreport: In January 2026, there was a noted 5% increase in critical vulnerabilities, with 23 high-impact issues identified. Among these, the exploitation of a significant Microsoft Office zero-day vulnerability (CVE-2026-21509) by Russian state-sponsored group APT28 highlighted ongoing threats to enterprise technologies. This vulnerability, which relates to the reliance on untrusted inputs in security decisions, enabled APT28 to utilize weaponized Rich Text Format (RTF) files to deliver various malicious implants, including MiniDoor, PixyNetLoader, and Covenant Grunt. The exploitation chain initiated with an RTF file that bypassed Office OLE mitigations. The attackers deployed MiniDoor as an Outlook VBA script for email collection, while PixyNetLoader, which created a mutex for persistence, allowed further attacks. A notable aspect of this operation was the use of geography-based evasion to limit the delivery of the malicious payloads, demonstrating the sophistication of the APT28 attacks. In addition to Microsoft, other vendors such as SmarterTools and Ivanti were significantly affected, with SmarterTools reporting multiple critical vulnerabilities allowing authentication bypass and remote code execution (RCE). Specifically, CVE-2026-23760 identified a privilege escalation flaw in SmarterMail, permitting unauthenticated users to reset passwords, demonstrating serious flaws in expected security protocols. Furthermore, the Modular DS WordPress plugin was found to have multiple vulnerabilities, CVE-2026-23550 and CVE-2026-23800, that allowed attackers to gain administrator access without authentication. These vulnerabilities emphasize the risk of widespread exploitation due to the centralized management of multiple WordPress sites.

    Post summary

    The report highlights that Russian state-sponsored APT28 actively exploited CVE-2026-21509 via weaponized RTF files, deploying tools such as MiniDoor and PixyNetLoader, and also notes additional critical vulnerabilities in SmarterMail and WordPress plugins.

    0000074
    589 followersView on X
  • y1 uda@abyo software@y1uda
    Disclosure

    CVE-2026-23550: Modular DSの認証バイパス(CVSS 10.0) [CVSS 10.0 Critical] | Nyambush セキュリティブログ https://nyambush.app/blog/wp-modular-ds-privesc #Nyambush #WordPress #WPSec #セキュリティ

    Post summary

    A blog post announces a newly disclosed authentication bypass vulnerability in Modular DS, rated critical with a CVSS score of 10.0.

    0000058
    175 followersView on X
  • Glitch News@glitch4techs
    Active Exploitation

    خطر داهم يهدد مواقع #ووردبريس! 🚨 ثغرة أمنية حرجة (CVE-2026-23550) في إضافة #ModularDS تُستغل حالياً للسماح للمهاجمين باكتساب صلاحيات إدارية دون مصادقة. الثغرة ذات خطورة قصوى (CVSS 10.0) وتؤثر على الإصدارات <= 2.5.1. #احمموقعك وحدث الإضافة فوراً إلى الإصدار 2.5.2. #أمنسيبراني #تحديثأمني 🔗 https://thehackernews.com/2026/01/critical-wordpress-modular-ds-plugin.html

    Post summary

    CVE‑2026‑23550 in the ModularDS WordPress plugin is actively exploited in the wild, allowing unauthenticated attackers to gain admin privileges. A patch (v2.5.2) is available and should be applied urgently.

    0000048
    19 followersView on X

Explore more