logo

Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access

ID: 0f9cd9f2-e057-50c1-b6f8-7fc145143e91

STIX ID: report--0f9cd9f2-e057-50c1-b6f8-7fc145143e91

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Tamilselvan

...
...

A critical vulnerability (CVE-2026-19598, CVSS 9.8) in the Pods WordPress plugin (affecting versions through 3.3.9) lets unauthenticated actors bypass the pods_admin AJAX router’s security checks due to an error-handling path that fails to terminate execution; attackers can reach admin-level methods (including password overwrite) and fully compromise sites. Wordfence validated and reported the issue, deployed temporary firewall rules on August 12, 2026, and the Pods team released patched versions (latest 3.3.9.1 and multiple backports) on August 14; administrators are advised to update, review admin accounts, and investigate suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.