Stored Cross-Site Scripting Vulnerability in Pods Plugin for WordPress
CVE-2026-76573
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 September 2026
What is CVE-2026-76573?
The Pods plugin for WordPress contains a vulnerability that allows for Stored Cross-Site Scripting (XSS) via the 'not_found' shortcode attribute. This issue arises from inadequate input sanitization and output escaping, which enables authenticated attackers with contributor-level access or higher to inject malicious web scripts into pages. When users access these compromised pages, the scripts execute, potentially leading to a range of malicious activities, including data theft and session hijacking.
Affected Version(s)
Pods β Custom Content Types and Fields 0 <= 3.3.9.1