A security vulnerability has been identified in the Pods – Custom Content Types and Fields plugin for WordPress, a common tool used to manage custom content on many websites. The flaw affects every version of the plugin up to and including 3.3.9. The bug breaks the plugin's built-in security access controls, meaning people who do not have a login for your site can bypass all standard checks. This allows unauthenticated attackers to gain full administrator access to your site, overwrite the password of any user account (including the site owner's), take complete control of the site, or perform other high-level administrative actions without permission.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-19598