CVE-2026-23550 is a critical Incorrect Privilege Assignment vulnerability in the Modular DS WordPress plugin, affecting versions up to 2.5.1, which allows for unauthenticated privilege escalation. With a CVSS score of 10.0, this flaw has a network attack vector, low complexity, and requires no privileges or user interaction. This leads to complete compromise of confidentiality, integrity, and availability, effectively enabling full administrative takeover. The vulnerability is being actively exploited in the wild, with Nuclei templates available for detection or exploitation. It has garnered significant community and media attention, highlighting its immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Modular DS | Modular DS | >= 0, <= 2.5.1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.