Privilege Escalation Vulnerability in Pods Plugin for WordPress
CVE-2026-19598

9.8CRITICAL

What is CVE-2026-19598?

The Pods – Custom Content Types and Fields plugin for WordPress has a vulnerability that allows privilege escalation through an authorization bypass. This issue affects all versions up to 3.3.9 and arises from the pods_admin AJAX router mishandling access controls. Specifically, the error handling mechanism improperly manages authentication checks, making it possible for unauthenticated attackers to gain administrator privileges or change user passwords, thereby compromising the entire site. Website owners must take immediate action to ensure their installations are updated and secure.

Affected Version(s)

Pods – Custom Content Types and Fields 2.8 <= 2.8.23.3

Pods – Custom Content Types and Fields 2.9 <= 2.9.19.3

Pods – Custom Content Types and Fields 3.0 <= 3.0.10.3

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nhien Pham (nhienit)
thevietronin
.