CVE-2026-19598 (matched: php)

  • Sunday, 16th August, 2026
  • 16:07pm

A security vulnerability has been identified in the Pods – Custom Content Types and Fields plugin, a common tool used to add custom content types and fields to WordPress websites. All versions of the plugin up to and including 3.3.9 are impacted by this flaw.

The issue breaks the plugin’s built-in security checks that are designed to block unauthorized users from accessing sensitive site administration functions. Due to an error in how the plugin processes access requests, these safeguards are completely bypassed for users who are not logged into your WordPress site at all.

This creates serious risk for your site: unauthenticated attackers could exploit the flaw to grant themselves full administrator access, or change the password of any user account on your site, including the primary site owner’s account. This would allow an attacker to take full control of your website.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-19598

« Back