Detects WordPress installs running the Modular DS (modular-connector) plugin at version 2.5.1 or earlier. The plugin's isDirectRequest() method accepts origin=mo to bypass all authentication checks on the login REST endpoint, allowing unauthenticated attackers to obtain a full administrator session cookie. Actively exploited in the wild since January 2026, affecting 40,000+ installations.
Is your app exploitable through CVE-2026-23550?
Scan your domain free