Executive brief
Pods is a popular WordPress plugin for building custom content types and managing data. The plugin incorrectly validates display callbacks, allowing authenticated users with author role or higher to execute arbitrary system commands on the web server. This can lead to complete server compromise, data theft, and website defacement.
Technical details
The Pods plugin fails to properly sanitize and validate display callback function names, allowing an attacker to bypass the restricted display-callback security mode. An authenticated user with author role or above can inject arbitrary PHP functions (such as system()) into a Pods shortcode or template tag via the helper attribute or template syntax. The vulnerability requires the site to have display callbacks set to "Restricted" mode (default for sites with Pods versions prior to 3.1). An attacker with author role creates a post with a malicious shortcode containing a restricted function name (e.g., "SyStEm") in the helper parameter; the callback comparison logic fails due to case-sensitivity or string matching flaws, allowing the function to execute server-side commands. The fix is available in version 3.3.9.1.
Affected products
- The Pods Project Pods before 3.3.9.1
Timeline
- 2026-08-24: disclosed
- 2026-08-26: advisory
- 2026-08-26: patched: Fixed in version 3.3.9.1