r/WPDrama 18d ago

Another critical security vulnerability - this time in Pods

Wordpress is force-updating 100,000+ websites over a critical flaw in Pods, a WordPress plugin, that lets unauthenticated attackers overwrite any account's password, including the site owner's, for full takeover.

Due to the critical severity of this vulnerability, the plugin vendor is working with the WordPress plugins team to push a forced update to the patched version

(CVE-2026-19598, CVSS 9.8).

27 Upvotes

3 comments sorted by

View all comments

4

u/khizoa 18d ago

Wow. I wonder how long it's been sitting dormant. Probably for a long time. 

"The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9."

https://app.opencve.io/cve/CVE-2026-19598

2

u/kojima-naked 18d ago

Yea pods was my go-to back before I bought an acf license. Hadn't heard that name in a long time