CVE-2026-23550

CRITICAL EXPLOITED NUCLEI

Modular DS <= 2.5.1 - Incorrect Privilege Assignment

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2026-23550 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 8 public exploits from researchers including XiaomingX, dzmind2312, O99099O. A Nuclei detection template is also available.

AI-analyzed exploit summary This PoC exploits a vulnerability in the Modular DS WordPress plugin, performing privilege escalation via admin-ajax.php and uploading a PHP shell and verification marker. It includes multi-threading for mass exploitation and logging of vulnerable targets.

Description

Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1.

Exploits (8)

github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-23550

This PoC exploits a vulnerability in the Modular DS WordPress plugin, performing privilege escalation via admin-ajax.php and uploading a PHP shell and verification marker. It includes multi-threading for mass exploitation and logging of vulnerable targets.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress Modular DS plugin
No auth needed
Prerequisites: WordPress site with vulnerable Modular DS plugin installed
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec SCANNER 1 stars
by dzmind2312 · remote
https://github.com/dzmind2312/Mass-CVE-2026-23550-Exploit

This is a multi-threaded Python scanner for CVE-2026-23550, which exploits an unauthenticated admin bypass vulnerability in the WordPress Modular DS plugin. It verifies admin access by checking for WordPress admin cookies and dashboard access.

Classification
Scanner 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: WordPress Modular DS plugin ≤2.5.1
No auth needed
Prerequisites: List of target URLs with the vulnerable plugin installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by O99099O · poc
https://github.com/O99099O/By-Poloss..-..CVE-2026-23550

This PoC exploits a privilege escalation vulnerability in a WordPress plugin (Modular DS) to upload a PHP shell and a verification marker. It uses a multi-threaded approach to target multiple URLs.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress plugin Modular DS (version not specified)
No auth needed
Prerequisites: Target running vulnerable WordPress plugin · Access to admin-ajax.php and uploader.php endpoints
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by TheTorjanCaptain · remote
https://github.com/TheTorjanCaptain/CVE-2026-23550-PoC

This PoC demonstrates an unauthenticated admin access vulnerability in the Modular DS WordPress plugin (CVE-2026-23550) by exploiting a flawed REST API endpoint that bypasses authentication when the 'origin=mo' parameter is used.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Modular DS WordPress Plugin <=2.5.1
No auth needed
Prerequisites: Target running WordPress with Modular DS plugin <=2.5.1 · Access to the REST API endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER 1 stars
by cyberdudebivash · poc
https://github.com/cyberdudebivash/CYBERDUDEBIVASH-Modular-DS-CVE-2026-23550-Detector

This repository contains a non-exploitative scanner for detecting CVE-2026-23550 in the WordPress Modular DS plugin by checking the plugin's version via readme.txt. It is a legitimate security tool for vulnerability detection.

Classification
Scanner 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: WordPress Modular DS plugin <= 2.5.1
No auth needed
Prerequisites: Access to the target WordPress site's readme.txt file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github WORKING POC
by Cyber-DarkNay · shellremote
https://github.com/Cyber-DarkNay/CVE-2026-23550

The repository contains a functional Bash script that exploits an authentication bypass vulnerability in the Modular Connector WordPress plugin (≤ 2.5.1) by sending a crafted POST request with `{"origin":"mo"}` to obtain an admin session cookie.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Modular Connector WordPress Plugin ≤ 2.5.1
No auth needed
Prerequisites: Target running vulnerable Modular Connector plugin · Access to the REST API endpoint
devstral-2 · analyzed Jun 11, 2026 Full analysis →
nomisec WORKING POC
by DedsecTeam-BlackHat · remote
https://github.com/DedsecTeam-BlackHat/CVE-2026-23550

The repository contains a functional bash script that exploits CVE-2026-23550, targeting a vulnerability in Modular DS (version <= 2.5.1). The script automates the creation of a backdoor admin user and sends crafted HTTP requests to achieve remote code execution (RCE).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Modular DS <= 2.5.1
No auth needed
Prerequisites: network access to target · target running Modular DS <= 2.5.1
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC
by epsilonpoint88-glitch · poc
https://github.com/epsilonpoint88-glitch/EpSiLoNPoInT-

This repository contains an advanced obfuscation tool (EpSiLoNPoInTFuCK) designed to evade detection for exploits targeting CVE-2026-0920. It includes multi-layered obfuscation techniques such as XOR encryption, homoglyph substitution, and dead code injection.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Complex
Reliability
Theoretical
Target: Unknown (obfuscation tool for CVE-2026-0920)
No auth needed
Prerequisites: Python environment · Target vulnerability (CVE-2026-0920)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Modular DS - Broken Access Control
HIGHVERIFIEDby DhiyaneshDk
FOFA: body="/plugins/modular-connector/"

Scores

CVSS v3 9.8
EPSS 0.1891
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-01-14
CWE
CWE-266
Status published
Products (1)
Modular DS/Modular DS < 2.5.1
Published Jan 14, 2026
Tracked Since Feb 18, 2026