Executive brief
Panda Pods Repeater Field, a WordPress plugin used to manage complex data entry fields, contains a security flaw in its access control settings. An unauthorized user could potentially exploit incorrectly configured security levels to perform actions they should not be allowed to do. This could lead to unauthorized modifications of site content or settings, though the overall risk is considered medium.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Panda Pods Repeater Field plugin for WordPress through version 1.5.12. The flaw stems from insufficient validation of access control security levels, which can be exploited by unauthenticated attackers over the network. Depending on the specific configuration, an attacker may be able to perform unauthorized actions or modify data. The issue is resolved in version 1.5.13.
Affected products
- Coding Panda Panda Pods Repeater Field <= 1.5.12
Timeline
- 2026-01-18: other: Vulnerability reported by Nabil Irawan
- 2026-02-17: advisory: Patchstack published advisory
- 2026-04-08: disclosed: CVE published to NVD
- 2026-02-17: patched: Version 1.5.13 released to address the issue