Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the WordPress Modular DS plugin to the latest available version (at least 2.6.0).
Vendor Workaround
Patchstack RapidMitigate virtual patch.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 19 Jan 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Modular
Modular modular Wordpress Wordpress wordpress |
|
| Vendors & Products |
Modular
Modular modular Wordpress Wordpress wordpress |
Fri, 16 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 16 Jan 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 before 2.6.0. | |
| Title | WordPress Modular DS plugin <= 2.5.2 - Privilege Escalation vulnerability | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-28T16:14:47.248Z
Reserved: 2026-01-16T14:15:17.504Z
Link: CVE-2026-23800
Updated: 2026-01-16T20:58:34.995Z
Status : Deferred
Published: 2026-01-16T21:15:52.037
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-23800
No data.
OpenCVE Enrichment
Updated: 2026-04-18T19:15:10Z