CVE-2026-19598

9.8

sc0ttkclark · Pods – Custom Content Types and Fields

The Pods WordPress plugin is vulnerable to unauthenticated privilege escalation due to an authorization bypass in the AJAX router.

Executive summary

A critical authorization bypass in the Pods WordPress plugin enables unauthenticated attackers to escalate privileges to Administrator, granting full site control.

Vulnerability

The pods_admin AJAX router fails to properly terminate requests upon failed authorization checks, allowing unauthenticated users to bypass security gates. This flaw permits attackers to perform administrative actions or overwrite user passwords, including those of site owners.

Business impact

This vulnerability carries a CVSS score of 9.8, reflecting the highest level of risk to confidentiality, integrity, and availability. Unauthorized administrative access allows attackers to exfiltrate sensitive data, inject malicious content, or permanently compromise the site infrastructure.

Remediation

Immediate Action: Update the Pods – Custom Content Types and Fields plugin to version 2.8.23.4 or the latest available secure version immediately.

Proactive Monitoring: Review administrative user accounts for unauthorized additions or password changes that occurred prior to patching.

Compensating Controls: Utilize a Web Application Firewall to filter requests targeting the pods_admin AJAX endpoint and restrict access to administrative interfaces.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of this privilege escalation flaw, all affected installations must be updated immediately. Failure to patch allows for complete site takeover, making this a top priority for security teams.