All verified exploits

CVE-2026-23550 Unauthenticated Admin Access via Authentication Bypass

Deterministic critical WordPress Added cve-verified-cve-2026-23550

Detects WordPress installs running the Modular DS (modular-connector) plugin at version 2.5.1 or earlier. The plugin's isDirectRequest() method accepts origin=mo to bypass all authentication checks on the login REST endpoint, allowing unauthenticated attackers to obtain a full administrator session cookie. Actively exploited in the wild since January 2026, affecting 40,000+ installations.

Related WordPress exploits

Is your app exploitable through CVE-2026-23550?

Scan your domain free