CVE-2026-19598 (matched: php)

  • Sunday, 16th August, 2026
  • 22:07pm

A security vulnerability has been identified in the Pods – Custom Content Types and Fields plugin for WordPress, a tool many site owners use to build custom content types and field structures for their sites. The flaw impacts all versions of the plugin up to and including 3.3.9. The issue stems from a bug in how the plugin runs its standard security checks when operating in a specific JSON compatibility mode. Normally, these checks block unauthorized users from accessing sensitive admin functions, but the bug causes failed checks to only be written to a server error log instead of blocking the request entirely, effectively disabling all security guards for these requests. This gap allows unauthenticated attackers (people who are not logged into your site at all) to exploit the flaw. They can grant themselves full administrator access to your site, change the password for any user account including the site owner’s, or carry out other admin-level actions that let them take complete control of your website.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-19598

« Back