Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access
ID: 0f600016-2d3a-5b3a-8e40-5fde60ed0aed
STIX ID: report--0f600016-2d3a-5b3a-8e40-5fde60ed0aed
Feed Name: GBHackers
**Critical CVE-2026-19598 in Pods plugin:** A high-severity (CVSS 9.8) flaw in the Pods WordPress plugin's pods_admin AJAX router can be exploited by unauthenticated attackers to escalate privileges to site administrator (e.g., via the save_user API), potentially allowing full site takeover; Wordfence disclosed the issue, patches and backports were released (including 3.3.9.1), and site owners are urged to update immediately, review admin accounts, reset passwords if compromise is suspected, and inspect logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
