Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access
ID: 0f9cd9f2-e057-50c1-b6f8-7fc145143e91
STIX ID: report--0f9cd9f2-e057-50c1-b6f8-7fc145143e91
Feed Name: Cyber Press
A critical vulnerability (CVE-2026-19598, CVSS 9.8) in the Pods WordPress plugin (affecting versions through 3.3.9) lets unauthenticated actors bypass the pods_admin AJAX router’s security checks due to an error-handling path that fails to terminate execution; attackers can reach admin-level methods (including password overwrite) and fully compromise sites. Wordfence validated and reported the issue, deployed temporary firewall rules on August 12, 2026, and the Pods team released patched versions (latest 3.3.9.1 and multiple backports) on August 14; administrators are advised to update, review admin accounts, and investigate suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
