Privilege Escalation Vulnerability in Pods Plugin for WordPress
CVE-2026-19598

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 August 2026

Badges

πŸ“ˆ TrendedπŸ“ˆ Score: 4,150πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2026-19598?

CVE-2026-19598 is a critical privilege escalation vulnerability found in the Pods plugin for WordPress, specifically impacting all versions up to and including 3.3.9. The Pods plugin is utilized for creating custom content types and fields within WordPress sites, enhancing their functionality. This vulnerability arises due to a flaw in the pods_admin AJAX router, which mishandles access checks, including authorization and capability validations. As a result, the security barriers designed to protect user accounts and site integrity fail to function properly. The vulnerability allows unauthenticated attackers to escalate their privileges to that of an Administrator. This not only permits the attackers to take control of the site but also enables them to overwrite any user account password, including that of the site owner, leading to a complete site takeover.

Potential impact of CVE-2026-19598

  1. Site Takeover: Attackers can gain administrative control, enabling them to manipulate site content, access sensitive data, and modify configurations, leading to potential data loss and reputational damage.

  2. Unauthorized User Access: The ability to overwrite user passwords means that attackers can impersonate legitimate users, increasing the risk of further exploitation and unauthorized actions within the site.

  3. Widespread Exploitation Risk: Given that the vulnerability affects a widely used plugin in numerous WordPress installations, the risk of mass exploitation is significant, potentially affecting thousands of websites and putting sensitive user data at risk.

Affected Version(s)

Pods – Custom Content Types and Fields 2.8 <= 2.8.23.3

Pods – Custom Content Types and Fields 2.9 <= 2.9.19.3

Pods – Custom Content Types and Fields 3.0 <= 3.0.10.3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • πŸ“ˆ

    Vulnerability started trending

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nhien Pham (nhienit)
thevietronin
.