Skip to content
Noroxi

Pods – Custom Content Types and Fields

pods · plugin

Known security vulnerabilities for Pods – Custom Content Types and Fields. Find out in seconds which version runs on your site with WP Lens.

9 known vulnerabilities

1 critical · 1 with public exploit code · latest Sep 5, 2026

Vulnerabilities

  • CVE-2026-19598

    Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router

    Critical 9.8
  • CVE-2023-6999→ 2.7.31

    Pods - Custom Content Types and Fields - Authenticated (Contributor+) Remote Code Execution

    High 8.8
  • CVE-2023-6967→ 2.7.31

    Pods - Custom Content Types and Fields - Authenticated (Contributor+) SQL Injection via Shortcode

    High 8.8
  • CVE-2023-23790

    WordPress Pods Plugin <= 2.9.10.2 is vulnerable to Cross Site Request Forgery (CSRF)

    High 8.8
  • CVE-2026-54191

    WordPress Pods plugin <= 3.3.8 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2014-7957

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote attackers to hijack the

    Medium 6.8
  • CVE-2026-76573

    Pods <= 3.3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'not_found' Shortcode Attribute

    Medium 6.4
  • CVE-2024-3956

    Pods – Custom Content Types and Fields <= 3.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pod Form Redirect URL

    Medium 5.4
  • CVE-2023-6965→ 2.7.31

    Pods - Custom Content Types and Fields - Missing Authorization

    Medium 4.3

← Back to directory