plugin

Pods Vulnerabilities

37 known security issues reported for the Pods WordPress plugin. Most recent disclosed Aug 15, 2026.

4 critical 4 high 9 medium

Running Pods on your site? Check whether your installed version is affected.

Scan your site free

Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router

critical

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login e...

CVSS:
9.8
Affected:
2.8 – 2.8.23.3, 2.9 – 2.9.19.3, 3.0 – 3.0.10.3, 3.1 – 3.1.4.1, 3.2 – 3.2.8.2, 3.3 – 3.3.9
Fixed in:
2.8.23.4
Disclosed:
Aug 15, 2026

CVE-2026-19598 on NVD →

Pods – Custom Content Types and Fields <= 3.3.8 - Unauthenticated Stored Cross-Site Scripting

high

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute...

CVSS:
7.2
Affected:
up to 3.3.8
Fixed in:
3.3.9
Disclosed:
Jun 15, 2026

CVE-2026-54191 on NVD →

Pods – Custom Content Types and Fields <= 3.2.8.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissio...

CVSS:
4.4
Affected:
up to 3.2.8.1
Fixed in:
3.2.8.2
Disclosed:
Mar 2, 2025

CVE-2025-1446 on NVD →

Pods &#8211; Custom Content Types and Fields [pods] < 3.2.8.1

unknown

[en] The Pods WordPress plugin before 3.2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 3.2.8.1
Fixed in:
3.2.8.1
Disclosed:
Jan 6, 2025

CVE-2024-11849 on NVD →

Pods – Custom Content Types and Fields <= 3.2.8 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...

CVSS:
4.4
Affected:
up to 3.2.8
Fixed in:
3.2.8.1
Disclosed:
Dec 16, 2024

CVE-2024-11849 on NVD →

Pods &#8211; Custom Content Types and Fields [pods] < 3.2.7.1

unknown

[en] The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 3.2.7.1
Fixed in:
3.2.7.1
Disclosed:
Nov 5, 2024

CVE-2024-9883 on NVD →

Pods <= 3.2.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...

CVSS:
4.4
Affected:
up to 3.2.7
Fixed in:
3.2.7.1
Disclosed:
Oct 15, 2024

CVE-2024-9883 on NVD →

Pods &#8211; Custom Content Types and Fields [pods] < 3.2.2

unknown

[en] Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send tha...

Affected:
up to 3.2.2
Fixed in:
3.2.2
Disclosed:
Jun 25, 2024

CVE-2024-6297 on NVD →

Several WordPress.org Plugins <= Various Versions - Injected Backdoor

critical

Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that dat...

CVSS:
10
Affected:
3.2.3 – 3.2.3
Fixed in:
3.2.4
Disclosed:
Jun 24, 2024

CVE-2024-6297 on NVD →

Pods &#8211; Custom Content Types and Fields [pods] < 3.2.1.1

unknown

[en] The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pod Form widget in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers...

Affected:
up to 3.2.1.1
Fixed in:
3.2.1.1
Disclosed:
May 10, 2024

CVE-2024-3956 on NVD →

Pods – Custom Content Types and Fields <= 3.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pod Form Redirect URL

medium

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pod Form widget in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wit...

CVSS:
5.4
Affected:
up to 3.2.1
Fixed in:
3.2.1.1
Disclosed:
May 9, 2024

CVE-2024-3956 on NVD →

Pods &#8211; Custom Content Types and Fields [pods] < 3.1

unknown

[en] The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existi...

Affected:
up to 3.1
Fixed in:
3.1
Disclosed:
Apr 9, 2024

CVE-2023-6967 on NVD →

Pods &#8211; Custom Content Types and Fields [pods] < 3.0.10.2

unknown

[en] The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This is due to the fact that the plugin allows the use of a file inclusion feature via shortcode. This makes it p...

Affected:
up to 3.0.10.2
Fixed in:
3.0.10.2
Disclosed:
Apr 9, 2024

CVE-2023-6965 on NVD →

Pods &#8211; Custom Content Types and Fields [pods] < 3.1

unknown

[en] The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possible for authenticated attackers, with contributor level access or higher, to ex...

Affected:
up to 3.1
Fixed in:
3.1
Disclosed:
Apr 9, 2024

CVE-2023-6999 on NVD →

Pods - Custom Content Types and Fields - Authenticated (Contributor+) Remote Code Execution

high

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possible for authenticated attackers, with contributor level access or higher, to execute...

CVSS:
8.8
Affected:
up to 2.7.31, 2.8 – 2.8.23.2, 3 – 3.0.10.2
Fixed in:
2.7.31.2
Disclosed:
Mar 28, 2024

CVE-2023-6999 on NVD →

Pods - Custom Content Types and Fields - Authenticated (Contributor+) SQL Injection via Shortcode

high

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQ...

CVSS:
8.8
Affected:
up to 2.7.31, 2.8 – 2.8.23.2, 3 – 3.0.10.2
Fixed in:
2.7.31.2
Disclosed:
Mar 28, 2024

CVE-2023-6967 on NVD →

Pods - Custom Content Types and Fields - Missing Authorization

medium

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This is due to the fact that the plugin allows the use of a file inclusion feature via shortcode. This makes it possib...

CVSS:
4.3
Affected:
up to 2.7.31, 2.8 – 2.8.23.2, 3 – 3.0.10.2
Fixed in:
2.7.31.2
Disclosed:
Mar 28, 2024

CVE-2023-6965 on NVD →

Pods &#8211; Custom Content Types and Fields [pods] < 2.9.11

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Pods Framework Team Pods – Custom Content Types and Fields plugin <= 2.9.10.2 versions.

Affected:
up to 2.9.11
Fixed in:
2.9.11
Disclosed:
May 3, 2023

CVE-2023-23790 on NVD →

Pods <= 2.9.10.2 - Cross-Site Request Forgery

high

The Pods plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10.2. This is due to missing or incorrect nonce validation when deleting pods. This makes it possible for unauthenticated attackers to delete pods via forged request granted they can trick a site administrato...

CVSS:
7.1
Affected:
up to 2.9.10.2
Fixed in:
2.9.11
Disclosed:
Jan 20, 2023

CVE-2023-23790 on NVD →

Pods &#8211; Custom Content Types and Fields [pods] < 2.9.11

unknown

The Pods plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10.2. This is due to missing or incorrect nonce validation when deleting pods. This makes it possible for unauthenticated attackers to delete pods via forged request granted they can trick a site administrato...

Affected:
up to 2.9.11
Fixed in:
2.9.11
Disclosed:
Jan 20, 2023

Pods – Custom Content Types and Fields <= 2.7.28 - Authenticated (Admin+) Cross-Site Scripting

medium

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.7.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in p...

CVSS:
5.5
Affected:
up to 2.7.28
Fixed in:
2.7.29
Disclosed:
Aug 6, 2021

Pods &#8211; Custom Content Types and Fields [pods] < 2.7.29

unknown

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.7.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in p...

Affected:
up to 2.7.29
Fixed in:
2.7.29
Disclosed:
Aug 6, 2021

Pods &#8211; Custom Content Types and Fields [pods] < 2.7.27

unknown

[en] The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Menu Label' field parameter.

Affected:
up to 2.7.27
Fixed in:
2.7.27
Disclosed:
Jun 21, 2021

CVE-2021-24339 on NVD →

Pods &#8211; Custom Content Types and Fields [pods] < 2.7.27

unknown

[en] The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Singular Label' field parameter.

Affected:
up to 2.7.27
Fixed in:
2.7.27
Disclosed:
Jun 21, 2021

CVE-2021-24338 on NVD →

Pods <= 2.7.26 - Authenticated Stored Cross-Site Scripting via Menu Label field

medium

The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Menu Label' field parameter.

CVSS:
5.4
Affected:
2.4.4.2 – 2.7.26
Fixed in:
2.7.27
Disclosed:
Jan 15, 2021

CVE-2021-24339 on NVD →

Pods 2.4.4.1 - 2.7.26 - Authenticated Stored Cross-Site Scripting

medium

The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Singular Label' field parameter.

CVSS:
5.4
Affected:
2.4.4.1 – 2.7.27
Fixed in:
2.7.27
Disclosed:
Jan 15, 2021

CVE-2021-24338 on NVD →

Pods – Custom Content Types and Fields < 2.5.1.2 - SQL Injection

critical

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions before 2.5.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append a...

CVSS:
9.8
Affected:
up to 2.5.1.2
Fixed in:
2.5.1.2
Disclosed:
Mar 16, 2015

Pods &#8211; Custom Content Types and Fields [pods] < 2.5.1.2

unknown

Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Update the plugin.

Affected:
up to 2.5.1.2
Fixed in:
2.5.1.2
Disclosed:
Mar 16, 2015

Pods &#8211; Custom Content Types and Fields [pods] < 2.5.1.2

unknown

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions before 2.5.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append a...

Affected:
up to 2.5.1.2
Fixed in:
2.5.1.2
Disclosed:
Mar 16, 2015

Pods &#8211; Custom Content Types and Fields [pods] < 2.5

unknown

[en] Cross-site scripting (XSS) vulnerability in the Pods plugin before 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter in an edit action in the pods page to wp-admin/admin.php.

Affected:
up to 2.5
Fixed in:
2.5
Disclosed:
Jan 15, 2015

CVE-2014-7956 on NVD →

Pods &#8211; Custom Content Types and Fields [pods] < 2.5

unknown

[en] Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the toggled parameter in a toggle action in the pods-components page to w...

Affected:
up to 2.5
Fixed in:
2.5
Disclosed:
Jan 15, 2015

CVE-2014-7957 on NVD →

Pods <= 2.4.3 - Multiple Cross-Site Request Forgery

critical

Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the toggled parameter in a toggle action in the pods-components page to wp-adm...

CVSS:
9.6
Affected:
up to 2.4.3
Fixed in:
2.5
Disclosed:
Jan 12, 2015

CVE-2014-7957 on NVD →

Pods <= 2.4.3 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the Pods plugin before 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter in an edit action in the pods page to wp-admin/admin.php.

CVSS:
6.1
Affected:
up to 2.4.3
Fixed in:
2.5
Disclosed:
Jan 12, 2015

CVE-2014-7956 on NVD →

Pods &#8211; Custom Content Types and Fields [pods] < 2.5.1.2

unknown

Version/s Tested: 2.5.1.1 and previous Description: Pods is a popular custom content types and fields plugin for WordPress. In the PodsUI class, which is used to build Pods administration interfaces, the orderby SQL query is set via a GET variable, which was not properly sanitized. Technical Description: At...

Affected:
up to 2.5.1.2
Fixed in:
2.5.1.2

Pods &#8211; Custom Content Types and Fields [pods] < 2.7.29

unknown

The plugin is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability in multiple parameters.

Affected:
up to 2.7.29
Fixed in:
2.7.29

Pods &#8211; Custom Content Types and Fields [pods] < 2.8.23

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 2.8.23
Fixed in:
2.8.23

CVE-2023-33999 on NVD →

Pods &#8211; Custom Content Types and Fields [pods] < 3.2.8.2

unknown
Affected:
up to 3.2.8.2
Fixed in:
3.2.8.2

CVE-2025-1446 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database