Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
critical
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login e...
- CVSS:
- 9.8
- Affected:
- 2.8 – 2.8.23.3, 2.9 – 2.9.19.3, 3.0 – 3.0.10.3, 3.1 – 3.1.4.1, 3.2 – 3.2.8.2, 3.3 – 3.3.9
- Fixed in:
- 2.8.23.4
- Disclosed:
- Aug 15, 2026
CVE-2026-19598 on NVD →
Pods – Custom Content Types and Fields <= 3.3.8 - Unauthenticated Stored Cross-Site Scripting
high
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute...
- CVSS:
- 7.2
- Affected:
- up to 3.3.8
- Fixed in:
- 3.3.9
- Disclosed:
- Jun 15, 2026
CVE-2026-54191 on NVD →
Pods – Custom Content Types and Fields <= 3.2.8.1 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissio...
- CVSS:
- 4.4
- Affected:
- up to 3.2.8.1
- Fixed in:
- 3.2.8.2
- Disclosed:
- Mar 2, 2025
CVE-2025-1446 on NVD →
Pods – Custom Content Types and Fields [pods] < 3.2.8.1
unknown
[en] The Pods WordPress plugin before 3.2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 3.2.8.1
- Fixed in:
- 3.2.8.1
- Disclosed:
- Jan 6, 2025
CVE-2024-11849 on NVD →
Pods – Custom Content Types and Fields <= 3.2.8 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...
- CVSS:
- 4.4
- Affected:
- up to 3.2.8
- Fixed in:
- 3.2.8.1
- Disclosed:
- Dec 16, 2024
CVE-2024-11849 on NVD →
Pods – Custom Content Types and Fields [pods] < 3.2.7.1
unknown
[en] The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 3.2.7.1
- Fixed in:
- 3.2.7.1
- Disclosed:
- Nov 5, 2024
CVE-2024-9883 on NVD →
Pods <= 3.2.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...
- CVSS:
- 4.4
- Affected:
- up to 3.2.7
- Fixed in:
- 3.2.7.1
- Disclosed:
- Oct 15, 2024
CVE-2024-9883 on NVD →
Pods – Custom Content Types and Fields [pods] < 3.2.2
unknown
[en] Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send tha...
- Affected:
- up to 3.2.2
- Fixed in:
- 3.2.2
- Disclosed:
- Jun 25, 2024
CVE-2024-6297 on NVD →
Several WordPress.org Plugins <= Various Versions - Injected Backdoor
critical
Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that dat...
- CVSS:
- 10
- Affected:
- 3.2.3 – 3.2.3
- Fixed in:
- 3.2.4
- Disclosed:
- Jun 24, 2024
CVE-2024-6297 on NVD →
Pods – Custom Content Types and Fields [pods] < 3.2.1.1
unknown
[en] The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pod Form widget in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers...
- Affected:
- up to 3.2.1.1
- Fixed in:
- 3.2.1.1
- Disclosed:
- May 10, 2024
CVE-2024-3956 on NVD →
Pods – Custom Content Types and Fields <= 3.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pod Form Redirect URL
medium
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pod Form widget in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wit...
- CVSS:
- 5.4
- Affected:
- up to 3.2.1
- Fixed in:
- 3.2.1.1
- Disclosed:
- May 9, 2024
CVE-2024-3956 on NVD →
Pods – Custom Content Types and Fields [pods] < 3.1
unknown
[en] The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existi...
- Affected:
- up to 3.1
- Fixed in:
- 3.1
- Disclosed:
- Apr 9, 2024
CVE-2023-6967 on NVD →
Pods – Custom Content Types and Fields [pods] < 3.0.10.2
unknown
[en] The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This is due to the fact that the plugin allows the use of a file inclusion feature via shortcode. This makes it p...
- Affected:
- up to 3.0.10.2
- Fixed in:
- 3.0.10.2
- Disclosed:
- Apr 9, 2024
CVE-2023-6965 on NVD →
Pods – Custom Content Types and Fields [pods] < 3.1
unknown
[en] The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possible for authenticated attackers, with contributor level access or higher, to ex...
- Affected:
- up to 3.1
- Fixed in:
- 3.1
- Disclosed:
- Apr 9, 2024
CVE-2023-6999 on NVD →
Pods - Custom Content Types and Fields - Authenticated (Contributor+) Remote Code Execution
high
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possible for authenticated attackers, with contributor level access or higher, to execute...
- CVSS:
- 8.8
- Affected:
- up to 2.7.31, 2.8 – 2.8.23.2, 3 – 3.0.10.2
- Fixed in:
- 2.7.31.2
- Disclosed:
- Mar 28, 2024
CVE-2023-6999 on NVD →
Pods - Custom Content Types and Fields - Authenticated (Contributor+) SQL Injection via Shortcode
high
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQ...
- CVSS:
- 8.8
- Affected:
- up to 2.7.31, 2.8 – 2.8.23.2, 3 – 3.0.10.2
- Fixed in:
- 2.7.31.2
- Disclosed:
- Mar 28, 2024
CVE-2023-6967 on NVD →
Pods - Custom Content Types and Fields - Missing Authorization
medium
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This is due to the fact that the plugin allows the use of a file inclusion feature via shortcode. This makes it possib...
- CVSS:
- 4.3
- Affected:
- up to 2.7.31, 2.8 – 2.8.23.2, 3 – 3.0.10.2
- Fixed in:
- 2.7.31.2
- Disclosed:
- Mar 28, 2024
CVE-2023-6965 on NVD →
Pods – Custom Content Types and Fields [pods] < 2.9.11
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Pods Framework Team Pods – Custom Content Types and Fields plugin <= 2.9.10.2 versions.
- Affected:
- up to 2.9.11
- Fixed in:
- 2.9.11
- Disclosed:
- May 3, 2023
CVE-2023-23790 on NVD →
Pods <= 2.9.10.2 - Cross-Site Request Forgery
high
The Pods plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10.2. This is due to missing or incorrect nonce validation when deleting pods. This makes it possible for unauthenticated attackers to delete pods via forged request granted they can trick a site administrato...
- CVSS:
- 7.1
- Affected:
- up to 2.9.10.2
- Fixed in:
- 2.9.11
- Disclosed:
- Jan 20, 2023
CVE-2023-23790 on NVD →
Pods – Custom Content Types and Fields [pods] < 2.9.11
unknown
The Pods plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10.2. This is due to missing or incorrect nonce validation when deleting pods. This makes it possible for unauthenticated attackers to delete pods via forged request granted they can trick a site administrato...
- Affected:
- up to 2.9.11
- Fixed in:
- 2.9.11
- Disclosed:
- Jan 20, 2023
Pods – Custom Content Types and Fields <= 2.7.28 - Authenticated (Admin+) Cross-Site Scripting
medium
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.7.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in p...
- CVSS:
- 5.5
- Affected:
- up to 2.7.28
- Fixed in:
- 2.7.29
- Disclosed:
- Aug 6, 2021
Pods – Custom Content Types and Fields [pods] < 2.7.29
unknown
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.7.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in p...
- Affected:
- up to 2.7.29
- Fixed in:
- 2.7.29
- Disclosed:
- Aug 6, 2021
Pods – Custom Content Types and Fields [pods] < 2.7.27
unknown
[en] The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Menu Label' field parameter.
- Affected:
- up to 2.7.27
- Fixed in:
- 2.7.27
- Disclosed:
- Jun 21, 2021
CVE-2021-24339 on NVD →
Pods – Custom Content Types and Fields [pods] < 2.7.27
unknown
[en] The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Singular Label' field parameter.
- Affected:
- up to 2.7.27
- Fixed in:
- 2.7.27
- Disclosed:
- Jun 21, 2021
CVE-2021-24338 on NVD →
Pods <= 2.7.26 - Authenticated Stored Cross-Site Scripting via Menu Label field
medium
The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Menu Label' field parameter.
- CVSS:
- 5.4
- Affected:
- 2.4.4.2 – 2.7.26
- Fixed in:
- 2.7.27
- Disclosed:
- Jan 15, 2021
CVE-2021-24339 on NVD →
Pods 2.4.4.1 - 2.7.26 - Authenticated Stored Cross-Site Scripting
medium
The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Singular Label' field parameter.
- CVSS:
- 5.4
- Affected:
- 2.4.4.1 – 2.7.27
- Fixed in:
- 2.7.27
- Disclosed:
- Jan 15, 2021
CVE-2021-24338 on NVD →
Pods – Custom Content Types and Fields < 2.5.1.2 - SQL Injection
critical
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions before 2.5.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append a...
- CVSS:
- 9.8
- Affected:
- up to 2.5.1.2
- Fixed in:
- 2.5.1.2
- Disclosed:
- Mar 16, 2015
Pods – Custom Content Types and Fields [pods] < 2.5.1.2
unknown
Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands.
Update the plugin.
- Affected:
- up to 2.5.1.2
- Fixed in:
- 2.5.1.2
- Disclosed:
- Mar 16, 2015
Pods – Custom Content Types and Fields [pods] < 2.5.1.2
unknown
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions before 2.5.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append a...
- Affected:
- up to 2.5.1.2
- Fixed in:
- 2.5.1.2
- Disclosed:
- Mar 16, 2015
Pods – Custom Content Types and Fields [pods] < 2.5
unknown
[en] Cross-site scripting (XSS) vulnerability in the Pods plugin before 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter in an edit action in the pods page to wp-admin/admin.php.
- Affected:
- up to 2.5
- Fixed in:
- 2.5
- Disclosed:
- Jan 15, 2015
CVE-2014-7956 on NVD →
Pods – Custom Content Types and Fields [pods] < 2.5
unknown
[en] Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the toggled parameter in a toggle action in the pods-components page to w...
- Affected:
- up to 2.5
- Fixed in:
- 2.5
- Disclosed:
- Jan 15, 2015
CVE-2014-7957 on NVD →
Pods <= 2.4.3 - Multiple Cross-Site Request Forgery
critical
Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the toggled parameter in a toggle action in the pods-components page to wp-adm...
- CVSS:
- 9.6
- Affected:
- up to 2.4.3
- Fixed in:
- 2.5
- Disclosed:
- Jan 12, 2015
CVE-2014-7957 on NVD →
Pods <= 2.4.3 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the Pods plugin before 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter in an edit action in the pods page to wp-admin/admin.php.
- CVSS:
- 6.1
- Affected:
- up to 2.4.3
- Fixed in:
- 2.5
- Disclosed:
- Jan 12, 2015
CVE-2014-7956 on NVD →
Pods – Custom Content Types and Fields [pods] < 2.5.1.2
unknown
Version/s Tested: 2.5.1.1 and previous
Description:
Pods is a popular custom content types and fields plugin for WordPress. In the PodsUI class, which is used to build Pods administration interfaces, the orderby SQL query is set via a GET variable, which was not properly sanitized.
Technical Description:
At...
- Affected:
- up to 2.5.1.2
- Fixed in:
- 2.5.1.2
Pods – Custom Content Types and Fields [pods] < 2.7.29
unknown
The plugin is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability in multiple parameters.
- Affected:
- up to 2.7.29
- Fixed in:
- 2.7.29
Pods – Custom Content Types and Fields [pods] < 2.8.23
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 2.8.23
- Fixed in:
- 2.8.23
CVE-2023-33999 on NVD →
Pods – Custom Content Types and Fields [pods] < 3.2.8.2
unknown
- Affected:
- up to 3.2.8.2
- Fixed in:
- 3.2.8.2
CVE-2025-1446 on NVD →