A security vulnerability has been identified in the Pods plugin for WordPress, a tool used to create custom content types and fields for WordPress sites. The flaw affects all versions of the plugin up to and including version 3.3.9. The vulnerability breaks the plugin’s standard security protections, so people who do not have a login account for your website can bypass all access checks. This allows attackers without site login credentials to grant themselves full administrator access to your site, change the password for any user account (including the primary site owner account), take complete control of your website, or perform other actions that only site administrators are supposed to be allowed to do without permission.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-19598