Panda Pods Repeater Field <= 1.5.12 - Missing Authorization
medium
The Panda Pods Repeater Field plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.5.12. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.5.12
- Fixed in:
- 1.5.13
- Disclosed:
- Feb 17, 2026
CVE-2026-39658 on NVD →
Panda Pods Repeater Field [panda-pods-repeater-field] < 1.5.4
unknown
[en] The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permission.
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.4
- Disclosed:
- Jan 30, 2023
CVE-2022-4306 on NVD →
Panda Pods Repeater Field <= 1.5.3 - Reflected Cross-Site Scripting
medium
The Panda Pods Repeater Field for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'podid' parameter in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- CVSS:
- 5.4
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.4
- Disclosed:
- Dec 7, 2022
CVE-2022-4306 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database