CVE-2026-19598
sc0ttkclark Pods – Custom Content Types and Fields
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON meta-box-loader compatibility path only writes failures to the PHP error log and returns false instead of terminating the request, rendering all guards ineffective. This makes it possible for unauthen...
- CVSS
- 9.8
- EPSS
- 2.79% 85.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.16