CVE-2026-19598 (matched: php)

  • Monday, 17th August, 2026
  • 04:07am

A security flaw has been found in the Pods – Custom Content Types and Fields plugin for WordPress, which impacts all versions up to and including 3.3.9. This vulnerability lets people who don’t have an account or login for your site bypass the plugin’s normal access restrictions.

If taken advantage of, these unauthenticated users can gain full administrator access to your site, change the password for any user account (including the main site owner’s account), or carry out other administrative actions. This would allow them to take complete control of your website, including accessing, editing, or deleting your content and user information.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-19598

« Back