← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 15, 2026 · 17:25via CVEFeed

CVE-2026-19598 - Pods = 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router

Brief

CVE ID : CVE-2026-19598

Published : Aug. 15, 2026, 5:25 p. m.

  • 3 hours, 41 minutes ago

Description : The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.

  • 9.

The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON meta-box-loader compatibility path only writes failures to the PHP error log and returns false instead of terminating the request, rendering all guards ineffective.

Read more on CVEFeed