Close Menu
    What's Hot

    Goodwin University Data Breach Exposes Student Records

    May 15, 2026

    QR Code Phishing Attacks : How Quishing Scams Are Targeting Mobile Users

    May 15, 2026

    Gujarat Fake Trading App Cyber Fraud Case: ₹49 Lakh Investment Scam Exposes Rising Digital Fraud Threats

    May 14, 2026

    Australian Financial Firm Cybersecurity Failure 2026: FIIG Securities Fined $2.5 Million After Major Data Breach

    May 13, 2026

    Foxconn Ransomware Attack: 8TB Data Theft Claims Raise Major Supply Chain Security Concerns

    May 13, 2026
    Facebook X (Twitter) Instagram
    Friday, May 15
    CyberNexora News
    X (Twitter) Instagram LinkedIn
    • Home
    • Cyber Incidents
    • laws & government
    • Penalties
    • Learn & Protect
    • Resources
    • Contact Us
    Get Cyber Alerts
    CyberNexora News
    Home»Cyber Incidents»Critical WordPress Plugin Bug Actively Used to Take Over Websites

    Critical WordPress Plugin Bug Actively Used to Take Over Websites

    Critical WordPress Plugin Vulnerability Allows Unauthorized Admin Access
    Zeel_CyberexpertBy Zeel_CyberexpertJanuary 16, 2026Updated:March 4, 20263 Mins Read
    Facebook Twitter LinkedIn Email Telegram

    A serious security flaw has been discovered in a popular WordPress plugin called Modular DS, and attackers are already abusing it to take control of websites.

    The vulnerability allows anyone on the internet to gain administrator access to a site without needing a username or password. Because of this, affected websites can be fully hijacked — content can be changed, malicious code can be inserted, users can be redirected to scam pages, and private data can be stolen.

    The issue exists in all versions of Modular DS up to version 2.5.1 and has been fixed in version 2.5.2. The plugin is used on more than 40,000 websites, which makes this vulnerability especially dangerous.

    What exactly is happening?

    The plugin exposes a set of API endpoints used for internal communication. These endpoints were supposed to be protected behind authentication, but due to a logic flaw in how requests are verified, attackers can bypass this protection by simply adding specific parameters to their request.

    Once bypassed, attackers can access sensitive internal routes — including a login route — and force the system to log them in as an administrator. This gives them full control of the website.

    What attackers can do

    With administrator access, an attacker can:

    • Create new admin users
    • Modify or delete website content
    • Install malicious plugins or backdoors
    • Redirect visitors to phishing or scam pages
    • Steal user or system information

    In many cases, victims may not notice the compromise immediately, allowing attackers to stay hidden for long periods.

    Active exploitation confirmed

    Security teams have confirmed that this vulnerability is not theoretical — it is actively being used in real attacks. Malicious requests targeting Modular DS sites have been detected since January 13, 2026, and several websites have already been compromised through this flaw.

    What site owners should do

    Anyone using Modular DS should take immediate action:

    • Update the plugin to version 2.5.2 or newer
    • Review admin users for anything unfamiliar
    • Check server logs for suspicious API requests
    • Change all administrator passwords
    • Scan the site for injected or modified files

    If updating is not possible right now, the safest option is to temporarily disable the plugin.

    Why this matters

    This incident highlights how dangerous small design mistakes can become when internal systems are exposed to the public internet without proper verification. Even a single insecure parameter can be enough to break the entire security model of an application.

    Website owners should treat plugin security updates as critical, not optional — especially for plugins that manage authentication, backups, or server connections.

    Share. Facebook Twitter LinkedIn Email Telegram

    latest news

    Goodwin University Data Breach Exposes Student Records

    May 15, 2026

    QR Code Phishing Attacks : How Quishing Scams Are Targeting Mobile Users

    May 15, 2026

    Gujarat Fake Trading App Cyber Fraud Case: ₹49 Lakh Investment Scam Exposes Rising Digital Fraud Threats

    May 14, 2026

    Australian Financial Firm Cybersecurity Failure 2026: FIIG Securities Fined $2.5 Million After Major Data Breach

    May 13, 2026

    Foxconn Ransomware Attack: 8TB Data Theft Claims Raise Major Supply Chain Security Concerns

    May 13, 2026

    Google AI-Generated Zero-Day Exploit 2026: Cybersecurity Enters a New Era of AI-Powered Attacks

    May 12, 2026

    South Staffordshire Water Data Breach Fine 2026: ICO Issues Nearly £1 Million Penalty After Cybersecurity Failures

    May 11, 2026

    OWASP Mobile Top 10-2024: Critical Mobile App Security Risks Every Security Professional Should Know

    May 10, 2026

    LockBit 5.0 Ransomware Attack on VP Brands International: Cybersecurity Threat Analysis and Business Impact

    May 10, 2026

    Vidar Malware Campaign: Fake Software Downloads Used to Steal Corporate Credentials

    May 9, 2026
    Recent Posts
    • Goodwin University Data Breach Exposes Student Records
    • QR Code Phishing Attacks : How Quishing Scams Are Targeting Mobile Users
    • Gujarat Fake Trading App Cyber Fraud Case: ₹49 Lakh Investment Scam Exposes Rising Digital Fraud Threats
    Top Posts

    Goodwin University Data Breach Exposes Student Records

    May 15, 2026

    Unauthorized Access Incident at Coupang Exposes Customer Data

    December 29, 2025

    Significant Data Breach at Korean Air Subcontractor Exposes Employee Records

    December 29, 2025
    About

    CyberNexora Blog provides trusted cybersecurity news, attack analysis, and security awareness updates. Our goal is to educate and inform readers about emerging cyber threats and best protection practices.

    Facebook X (Twitter) Instagram Pinterest LinkedIn
    Pages
    • Home
    • Cyber Incidents
    • laws & government
    • Penalties
    • Learn & Protect
    • Resources
    • Contact Us

    Get Cyber Security Alerts

    Thanks! Please check your email to confirm subscription.

    • About CyberNexora News
    • Privacy Policy
    © 2026 CyberNexora News. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.