A security flaw has been found in the Pods – Custom Content Types and Fields plugin for WordPress, a tool many sites use to manage custom content and fields. All versions of this plugin up to and including version 3.3.9 are affected by the issue. The bug causes the plugin's security checks to be completely skipped, even for people who do not have a valid login or account for your site. This allows attackers to gain full administrator access to your WordPress site. They could change the password for any user account on the site, including the site owner's account, take complete control of the site, or perform any other action that should only be available to a site administrator.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-19598