ZeroHour

CVE-2026-23550

moderate

Incorrect Privilege Assignment in Modular DS WordPress Plugin Enables Admin Takeover

CVSS 3.1
9.8 critical
EPSS
21%p97
Published
()
Modified
AI analysis

The Modular DS (modular-connector) WordPress plugin contains an incorrect privilege assignment flaw (CWE-266) that allows privilege escalation and is rated critical at CVSS 9.8. Per the CVSS vector, the flaw is exploitable over a network with low attack complexity, no privileges required, and no user interaction, meaning a remote attacker can trigger it against any site running an affected version. Successful exploitation grants the attacker administrator-level access to the WordPress site, effectively a full admin takeover with high impact on confidentiality, integrity, and availability. Any WordPress site running Modular DS in versions up to and including 2.5.1 is affected. Security news reports indicate the flaw is being actively exploited in the wild to gain admin access, and EPSS assigns a 21.1% probability of exploitation within 30 days (97th percentile), though the flaw is not yet listed in CISA's KEV catalog.

What to do: Update the Modular DS connector plugin to the latest patched release (any version after 2.5.1) immediately, since the flaw is being actively exploited. Because successful exploitation grants full administrator access, audit affected sites for unexpected administrator accounts, altered user roles, and suspicious recent admin activity, and treat vulnerable installs as potentially compromised. If patching is not immediately possible, deactivate the plugin until the fixed version can be deployed.

Affected
Modular DS (modular-connector) WordPress pluginfrom n/a through <= 2.5.1 (all versions up to and including 2.5.1)
Estimated exposure
moderate≈10,000+ sites (estimated; no verified install count was provided) — No active-install count was included in the source data; the Modular DS connector is deployed primarily on WordPress sites connected to the Modular DS site-management platform, whose install base is plausibly in the tens of thousands, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1.

Ecosystems
WordPress
Weakness
CWE-266
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news