logo

Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access

ID: 0f600016-2d3a-5b3a-8e40-5fde60ed0aed

STIX ID: report--0f600016-2d3a-5b3a-8e40-5fde60ed0aed

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Divya

...
...

**Critical CVE-2026-19598 in Pods plugin:** A high-severity (CVSS 9.8) flaw in the Pods WordPress plugin's pods_admin AJAX router can be exploited by unauthenticated attackers to escalate privileges to site administrator (e.g., via the save_user API), potentially allowing full site takeover; Wordfence disclosed the issue, patches and backports were released (including 3.3.9.1), and site owners are urged to update immediately, review admin accounts, reset passwords if compromise is suspected, and inspect logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.