CVE-2026-19598 (matched: wordpress)

  • Saturday, 15th August, 2026
  • 22:05pm

A security vulnerability has been identified in the Pods – Custom Content Types and Fields plugin for WordPress, impacting all versions up to and including 3.3.9. This plugin is commonly used to add custom content types and fields to WordPress sites, so it may be installed on your website if you use it for customized content management.

The flaw works by bypassing the standard security checks that normally block unapproved users from accessing sensitive admin functions. This makes it possible for anyone without a login for your site to gain full administrator access to your WordPress dashboard, change the password for any user on your site (including your own account), or carry out other high-level admin actions.

If exploited, this would let an attacker take complete control of your website, modify or delete your content, and access any data stored on the site.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-19598

« Back