Junglewise Threat Intelligence

CVE-2026-54191: Pods Framework Pods plugin unauthenticated XSS

CVE-2026-54191 · Severity: high · CVSS 7.1 · Published 2026-06-16

Executive brief

The Pods plugin for WordPress, which is used to manage custom content types and fields, contains a security flaw that allows unauthorized attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could potentially hijack sessions, redirect users to malicious websites, or deface the site. This vulnerability is particularly concerning as it can be used in automated mass-exploit campaigns against many websites simultaneously.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in the Pods plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires a victim (typically a privileged user) to perform an action, such as clicking a malicious link or visiting a crafted page. Successful exploitation can lead to session hijacking, unauthorized actions in the context of the victim's browser, or site defacement. The issue is addressed in version 3.3.9.

Affected products

  • Pods Framework Team Pods Framework <= 3.3.8

Timeline

  • 2026-05-17: disclosed: Reported by Bonds via Patchstack VDP
  • 2026-06-15: advisory: Patchstack advisory published
  • 2026-06-16: patched: CVE record published and patch confirmed in version 3.3.9

References