CVE-2026-19598 (matched: php)

  • Sunday, 16th August, 2026
  • 04:06am

A security vulnerability has been found in the Pods – Custom Content Types and Fields plugin for WordPress, a popular tool that many site owners use to add custom content types and field features to their websites. The flaw affects all versions of the plugin up to and including 3.3.9.

The vulnerability works by bypassing all of the plugin’s built-in access checks that are supposed to block unapproved users from accessing sensitive site functions. This means attackers do not need to be logged into your WordPress site to exploit the flaw.

If successfully exploited, the flaw lets unauthenticated attackers either gain full administrator access to your site, giving them complete control over all your site’s content and settings, or overwrite the password for any user account on your site, including your own site owner account, to take over the site entirely.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-19598

« Back