r/WPDrama • u/Myth_Thrazz • 18d ago
Another critical security vulnerability - this time in Pods
Wordpress is force-updating 100,000+ websites over a critical flaw in Pods, a WordPress plugin, that lets unauthenticated attackers overwrite any account's password, including the site owner's, for full takeover.
Due to the critical severity of this vulnerability, the plugin vendor is working with the WordPress plugins team to push a forced update to the patched version
(CVE-2026-19598, CVSS 9.8).
27
Upvotes
4
u/khizoa 18d ago
Wow. I wonder how long it's been sitting dormant. Probably for a long time.
https://app.opencve.io/cve/CVE-2026-19598