CVE-2026-19598 (matched: php)

  • Saturday, 15th August, 2026
  • 22:06pm

A security flaw has been identified in the Pods – Custom Content Types and Fields plugin for WordPress, a tool used to build custom content structures on many WordPress sites. The flaw affects all versions of the plugin up to and including 3.3.9.

Normally, this plugin has built-in security checks designed to block unapproved users from accessing administrative functions. However, these checks are broken for a specific compatibility mode: instead of stopping unauthorized requests, they only write error messages to the site’s error log and allow the request to proceed, rendering all security guards ineffective.

This makes it possible for attackers who do not have any login access to your site to gain full administrator privileges, change the password of any user account (including the main site owner account), take over the entire site, or perform any other administrator-level action.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-19598

« Back