Junglewise Threat Intelligence

CVE-2026-19598: Pods Custom Content Types and Fields privilege escalation via authorization bypass

CVE-2026-19598 · Severity: critical · CVSS 9.8 · Published 2026-08-15

Executive brief

The Pods plugin for WordPress allows site administrators to create custom content types and fields without coding. A flaw in its AJAX request handling allows unauthenticated attackers to bypass all security checks and gain administrator access or reset any user's password, leading to complete site takeover. This affects all versions up to and including 3.3.9.

Technical details

The vulnerability is a privilege escalation via authorization bypass in the pods_admin AJAX router. The root cause is improper error handling: access control checks (method allowlist, nonce verification, login enforcement, and capability gates) are funneled through pods_error(), which under the JSON meta-box-loader compatibility path only logs failures to the PHP error log and returns false instead of terminating the request. This renders all security guards ineffective. Unauthenticated attackers can reach the AJAX endpoint over the network without prior authentication or user interaction, allowing them to escalate to Administrator or reset any user account password. No patch information is currently available for versions up to 3.3.9.

Affected products

  • Pods Pods Custom Content Types and Fields up to and including 3.3.9

Timeline

  • 2026-08-15: disclosed

References