Close Menu
    What's Hot

    LLM-Generated Mythic Agents: AI Creates Disposable Malware

    June 29, 2026

    VS Code Infostealer Attack: Critical npm Packages Hijacked

    June 29, 2026

    GLM-5.2 AI: Major Challenge to U.S. Cybersecurity

    June 29, 2026

    Zero Trust Architecture Guide: CISA Releases TIC 3.0 Framework

    June 28, 2026

    Signal Backup Recovery Key Phishing: Critical FBI Warning

    June 28, 2026
    Facebook X (Twitter) Instagram
    Tuesday, June 30
    CyberNexora News
    X (Twitter) Instagram LinkedIn
    • Home
    • Cyber Incidents
    • laws & government
    • Penalties
    • Learn & Protect
    • Resources
    • Contact Us
    Get Cyber Alerts
    CyberNexora News
    Home»Cyber Incidents»Critical WordPress Plugin Bug Actively Used to Take Over Websites

    Critical WordPress Plugin Bug Actively Used to Take Over Websites

    Critical WordPress Plugin Vulnerability Allows Unauthorized Admin Access
    Zeel_CyberexpertBy Zeel_CyberexpertJanuary 16, 2026Updated:March 4, 20263 Mins Read
    Facebook Twitter LinkedIn Email Telegram

    A serious security flaw has been discovered in a popular WordPress plugin called Modular DS, and attackers are already abusing it to take control of websites.

    The vulnerability allows anyone on the internet to gain administrator access to a site without needing a username or password. Because of this, affected websites can be fully hijacked — content can be changed, malicious code can be inserted, users can be redirected to scam pages, and private data can be stolen.

    The issue exists in all versions of Modular DS up to version 2.5.1 and has been fixed in version 2.5.2. The plugin is used on more than 40,000 websites, which makes this vulnerability especially dangerous.

    What exactly is happening?

    The plugin exposes a set of API endpoints used for internal communication. These endpoints were supposed to be protected behind authentication, but due to a logic flaw in how requests are verified, attackers can bypass this protection by simply adding specific parameters to their request.

    Once bypassed, attackers can access sensitive internal routes — including a login route — and force the system to log them in as an administrator. This gives them full control of the website.

    What attackers can do

    With administrator access, an attacker can:

    • Create new admin users
    • Modify or delete website content
    • Install malicious plugins or backdoors
    • Redirect visitors to phishing or scam pages
    • Steal user or system information

    In many cases, victims may not notice the compromise immediately, allowing attackers to stay hidden for long periods.

    Active exploitation confirmed

    Security teams have confirmed that this vulnerability is not theoretical — it is actively being used in real attacks. Malicious requests targeting Modular DS sites have been detected since January 13, 2026, and several websites have already been compromised through this flaw.

    What site owners should do

    Anyone using Modular DS should take immediate action:

    • Update the plugin to version 2.5.2 or newer
    • Review admin users for anything unfamiliar
    • Check server logs for suspicious API requests
    • Change all administrator passwords
    • Scan the site for injected or modified files

    If updating is not possible right now, the safest option is to temporarily disable the plugin.

    Why this matters

    This incident highlights how dangerous small design mistakes can become when internal systems are exposed to the public internet without proper verification. Even a single insecure parameter can be enough to break the entire security model of an application.

    Website owners should treat plugin security updates as critical, not optional — especially for plugins that manage authentication, backups, or server connections.

    Related Articles

  • Gravity SMTP Vulnerability 2026: API Keys Exposed Introduction: Gravity SMTP Vulnerability 2026 — Why It Matters The...
  • Cryptocurrency Wallet Drainer Attacks: How Fake Crypto Websites and Malicious Extensions Are Stealing Digital Assets Introduction: Rising Cryptocurrency Wallet Drainer Attacks Cryptocurrency Wallet Drainer Attacks...
  • GDPR Compliance in 2026: 7 Rules, Penalties & Why Every Website Needs It Introduction GDPR compliance has become mandatory for every website in...
  • Critical Linux Kernel Improper Authentication Vulnerability 2026 Explained Introduction The Linux Kernel Improper Authentication Vulnerability has emerged as...
  • Gogs 0-Day Vulnerability Exposes Critical Remote Code Execution Risk Introduction: Gogs 0-Day Vulnerability Raises Serious Security Concerns The Gogs...
  • Share. Facebook Twitter LinkedIn Email Telegram

    latest news

    LLM-Generated Mythic Agents: AI Creates Disposable Malware

    June 29, 2026

    VS Code Infostealer Attack: Critical npm Packages Hijacked

    June 29, 2026

    GLM-5.2 AI: Major Challenge to U.S. Cybersecurity

    June 29, 2026

    Zero Trust Architecture Guide: CISA Releases TIC 3.0 Framework

    June 28, 2026

    Signal Backup Recovery Key Phishing: Critical FBI Warning

    June 28, 2026

    Bucket Hijacking Attack: Critical Cloud Data Risk

    June 28, 2026

    GPT-5.6 Sol: OpenAI Unveils Secure AI Preview

    June 27, 2026

    Claude Mythos 5 Redeployment: Anthropic Confirms Return

    June 27, 2026

    TinyRCT Backdoor: Chinese APT Targets Southeast Asia

    June 27, 2026

    Pedit COW Exploit: Critical Linux Root Vulnerability

    June 26, 2026
    Recent Posts
    • LLM-Generated Mythic Agents: AI Creates Disposable Malware
    • VS Code Infostealer Attack: Critical npm Packages Hijacked
    • GLM-5.2 AI: Major Challenge to U.S. Cybersecurity
    Top Posts

    Unauthorized Access Incident at Coupang Exposes Customer Data

    December 29, 2025

    LLM-Generated Mythic Agents: AI Creates Disposable Malware

    June 29, 2026

    Significant Data Breach at Korean Air Subcontractor Exposes Employee Records

    December 29, 2025
    About

    CyberNexora Blog provides trusted cybersecurity news, attack analysis, and security awareness updates. Our goal is to educate and inform readers about emerging cyber threats and best protection practices.

    Facebook X (Twitter) Instagram Pinterest LinkedIn
    Pages
    • Home
    • Cyber Incidents
    • laws & government
    • Penalties
    • Learn & Protect
    • Resources
    • Contact Us

    Get Cyber Security Alerts

    Thanks! Please check your email to confirm subscription.

    • About CyberNexora News
    • Privacy Policy
    © 2026 CyberNexora News. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.