CVE-2026-19598 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 10:05am

A security vulnerability has been found in the Pods – Custom Content Types and Fields plugin for WordPress, affecting all versions up to and including 3.3.9. Normally, this plugin has built-in checks to block unapproved users from accessing sensitive site admin functions. A coding bug causes these checks to fail for visitors who do not have a login for your site: instead of blocking unauthorized requests, the bug only logs the failed check and lets the request proceed. This flaw allows unauthenticated attackers to gain full administrator access to your site, change the password for any user account (including the site owner’s account), take over your entire WordPress site, or perform other actions that should only be available to site administrators.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-19598

« Back