CVE-2026-19598
Description
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON meta-box-loader compatibility path only writes failures to the PHP error log and returns false instead of terminating the request, rendering all guards ineffective. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator or overwrite the password of any user account, including the site owner's, enabling complete site takeover, or perform another administrator action.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
5- ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and MoreThe Hacker News · Aug 31, 2026
- Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCEThe Hacker News · Aug 29, 2026
- WordPress Plugin Vulnerability Exposes 100,000 Sites to Complete Site Takeover AttacksCyber Security News · Aug 24, 2026
- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 10, 2026 to August 16, 2026)Wordfence Blog · Aug 21, 2026
- 100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in Pods WordPress PluginWordfence Blog · Aug 21, 2026