Impact
The Vulnerability is an Incorrect Privilege Assignment flaw in the Modular DS plugin, allowing an attacker to raise privileges beyond what is intended. This weakness, classified as CWE-266, can let a non‑privileged user acquire higher permissions, leading to unauthorized access to site data, configuration changes, or full control over the WordPress installation. The impact is direct compromise of confidentiality, integrity, and availability of the affected site.
Affected Systems
All WordPress sites that use Modular DS plugin version 2.5.2 or earlier up to but not including 2.6.0 are impacted. The plugin is commonly installed on public websites and managed via the WordPress admin interface.
Risk and Exploitability
The CVSS score of 10 indicates the highest severity. The EPSS score is less than 1%, suggesting that, although the flaw is severe, real‑world exploitation frequency is currently low or uncertain. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through the normal WordPress administrative interface or any authenticated user interface that includes the plugin. An attacker would need to exploit the incorrect privilege assignment to elevate their role without further authentication escalation.
OpenCVE Enrichment