Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-19598: WordPress Pods <= 3.3.9 - Unauthenticated Attackers Can Take Over Your Site

CVE-2026-19598 · published 19 days ago
Summary

The Pods plugin for WordPress has a security flaw that lets attackers take control of your site without needing a password. This could let them change passwords, delete content, or even lock you out of your own site. To stay safe, update the Pods plugin to the latest version as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
sc0ttkclark pods – custom content types and fields <= 2.8.23.3
Original advisory text
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON meta-box-loader compatibility path only writes failures to the PHP error log and returns false instead of terminating the request, rendering all guards ineffective. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator or overwrite the password of any user account, including the site owner's, enabling complete site takeover, or perform another administrator action.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS 3%
Type
CWE-863Incorrect Authorization
Timeline
Published15 Aug 2026
Updated2 Sep 2026
First seen15 Aug 2026
Sources
CVE-2026-19598 · MITRE
Monitor software like this
Free during beta