CVE-2026-19598 (matched: wordpress)

  • Monday, 17th August, 2026
  • 10:06am

A security flaw has been identified in the Pods – Custom Content Types and Fields plugin for WordPress, a tool many site owners use to build custom content structures and manage specialized data on their sites. All versions of this plugin up to and including version 3.3.9 are affected by this vulnerability. The issue stems from a bug in the plugin’s request handling that disables all its built-in security checks for administrative actions. Normally these checks block unapproved users from accessing sensitive admin functions, but the bug causes the checks to fail without stopping the request, meaning people who do not have a login to your site could gain full administrator access to your WordPress site. This could allow attackers to change the password of any user account on your site (including the site owner’s account), take complete control of your site, or perform other sensitive administrative actions without authorization.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-19598

« Back