A security flaw has been found in the WordPress plugin Pods – Custom Content Types and Fields, which is used to create custom content types and fields for WordPress sites. The vulnerability affects all versions of the plugin up to and including version 3.3.9.
The issue lets attackers bypass all of the plugin's built-in access security checks, even if the attacker does not have a login for your website at all.
If this flaw is exploited, bad actors can give themselves full administrator access to your site, change the password of any user account (including the main site owner's account), take complete control of your site, or perform other administrative actions.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-19598