{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/pods--custom-content-types-and-fields/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-19598"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Pods – Custom Content Types and Fields"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Pods - Custom Content Types and Fields plugin for WordPress is vulnerable to a critical privilege escalation and authorization bypass (CVE-2026-19598) affecting all versions up to and including 3.3.9. The vulnerability originates in the pods_admin AJAX router, which handles security checks such as nonce verification, authentication, and capability gates. Due to a design flaw in the meta-box-loader compatibility path, the plugin calls pods_error() upon failing security checks. Critically, instead of terminating the request, the function logs the error and returns false, allowing the execution flow to continue unchecked. An unauthenticated attacker can exploit this behavior to perform unauthorized administrative actions, including changing user passwords or escalating privileges to Administrator, ultimately leading to complete site takeover.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target WordPress site running the Pods plugin version 3.3.9 or earlier.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request targeting the pods_admin AJAX endpoint (typically wp-admin/admin-ajax.php).\u003c/li\u003e\n\u003cli\u003eAttacker directs the request to utilize the vulnerable meta-box-loader compatibility path.\u003c/li\u003e\n\u003cli\u003eAttacker omits or provides invalid security tokens (nonces) or credentials, triggering a validation failure.\u003c/li\u003e\n\u003cli\u003eThe plugin executes the pods_error() function, which records the failure to the PHP error log but fails to kill the script execution.\u003c/li\u003e\n\u003cli\u003eThe application continues execution as if the request were authorized.\u003c/li\u003e\n\u003cli\u003eAttacker submits parameters intended for an administrative action, such as a user password change or role update.\u003c/li\u003e\n\u003cli\u003eThe application processes the administrative request, resulting in site takeover or account compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to bypass all security guards in the affected plugin. This enables unauthorized account creation, modification of user passwords (including the administrator account), and the execution of arbitrary administrative functions. Depending on the site configuration, this likely leads to full site compromise and persistent access for the threat actor.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Pods - Custom Content Types and Fields plugin to the latest version immediately to patch CVE-2026-19598.\u003c/li\u003e\n\u003cli\u003eMonitor web server error logs for unexpected calls to pods_error() or evidence of pods_admin execution from unauthenticated sessions.\u003c/li\u003e\n\u003cli\u003eReview WordPress user account modifications and administrative role changes for anomalous activity during the relevant timeframe.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-15T18:19:56Z","date_published":"2026-08-15T18:19:56Z","id":"https://feed.craftedsignal.io/briefs/2026-08-pods-privilege-escalation/","summary":"The Pods plugin for WordPress contains an authorization bypass in its AJAX router that allows unauthenticated attackers to escalate privileges or take over administrative accounts.","title":"CVE-2026-19598: Authorization Bypass in Pods Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-08-pods-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Pods – Custom Content Types and Fields","version":"https://jsonfeed.org/version/1.1"}