CVE-2026-19598
published 2026-08-15CVE-2026-19598: The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and…
PriorityP184critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
2.79%
85.6th percentile
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON meta-box-loader compatibility path only writes failures to the PHP error log and returns false instead of terminating the request, rendering all guards ineffective. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator or overwrite the password of any user account, including the site owner's, enabling complete site takeover, or perform another administrator action.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sc0ttkclark | pods_custom_content_types_and_fields | 2.8 – 2.8.23.3 | — |
| sc0ttkclark | pods_custom_content_types_and_fields | 2.9 – 2.9.19.3 | — |
| sc0ttkclark | pods_custom_content_types_and_fields | 3.0 – 3.0.10.3 | — |
| sc0ttkclark | pods_custom_content_types_and_fields | 3.1 – 3.1.4.1 | — |
| sc0ttkclark | pods_custom_content_types_and_fields | 3.2 – 3.2.8.2 | — |
| sc0ttkclark | pods_custom_content_types_and_fields | 3.3 – 3.3.9 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
sc0ttkclark Pods Plugin up to 3.3.9 on WordPress AJAX Router pods_error authorization (EUVD-2026-59778)
vuldb·2026-08-15·CVSS 9.8
CVE-2026-19598 [CRITICAL] sc0ttkclark Pods Plugin up to 3.3.9 on WordPress AJAX Router pods_error authorization (EUVD-2026-59778)
A vulnerability was found in sc0ttkclark Pods Plugin up to 3.3.9 on WordPress. It has been rated as critical. Impacted is the function pods_error of the component AJAX Router. The manipulation leads to authorization bypass.
This vulnerability is referenced as CVE-2026-19598. Remote exploitation of the attack is possible. No exploit is available.
GHSA
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9.
ghsa_unreviewed·2026-08-15
CVE-2026-19598 [CRITICAL] CWE-863 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9.
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON meta-box-loader compatibility path only writes failures to the PHP error log and returns false instead of terminating the request, rendering all guards ineffective. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator or overwrite the password of any user account, including the site owner's, enabling complete site takeover, or perform another administrato
VulnCheck
Incorrect Authorization
vulncheck·2026·CVSS 9.8
CVE-2026-19598 [CRITICAL] Incorrect Authorization
Incorrect Authorization
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON meta-box-loader compatibility path only writes failures to the PHP error log and returns false instead of terminating the request, rendering all guards ineffective. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator or overwrite the password of any user account, including the site owner's, enabling complete site takeover, or per
No detection rules found.
Nuclei
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX Router
nuclei·CVSS 9.8
CVE-2026-19598 [CRITICAL] Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX Router
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX Router
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON meta-box-loader compatibility path only writes failures to the PHP error log and returns false instead of terminating the request, rendering all guards ineffective. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator or overwrite the password of any user account, including t
Hackernews
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
blogs_hackernews·2026-08-31
CVE-2026-81578 ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
The boring parts caused most of the trouble.
A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional.
Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept things moving. Different attacks, same useful mistake: something familiar was trusted without a second look.
Here is the week...
## ⚡ Threat of the
Hackernews
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
blogs_hackernews·2026-08-29·CVSS 9.8
CVE-2026-76581 [CRITICAL] Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution.
The vulnerabilities, according to Wordfence and Patchstack, are listed below -
CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in the WPMU DEV Dashboard plugin that could allow an unauthenticated attacker, on sites connected to WPMU DEV with Hub Single-Sign On (SSO) enabled and mapped to an
2026-08-15
Published
Exploited in the wild