Critical Privilege Escalation Vulnerability in Modular DS plugin affecting 40k+ Sites exploited in the wild
Reported exploitedModular DS pluginModular Connector Read at Patchstack
Below is the opening; the full story is at Patchstack.
From Patchstack
This blog post is about an Unauthenticated Privilege Escalation vulnerability in the Modular DS plugin. Patchstack has issued a mitigation rule to protect against exploitation of this vulnerability. If you’re a Modular DS user, please update to at least version 2.6.0.
This vulnerability was discovered and reported to Patchstack by Teemu Saarentaus from group.one.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.