The Pods plugin for WordPress, a tool used to build custom content types and fields for websites, has a security vulnerability affecting all versions up to and including 3.3.9. This flaw breaks the plugin's standard access checks, so unauthenticated attackers (people who do not have authorized login access to your site) can bypass all normal permission barriers.
Attackers can exploit this issue to grant themselves full administrator access to your site, or change the password of any user account on your site, including the account of the site owner. This would let them take complete control of your website and perform any action a site administrator would normally be allowed to carry out.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-19598