CVE-CVE-2026-19598
Severity
CRITICAL
CVSS Score
9.8
Description
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON meta-box-loader compatibility path only writes failures to the PHP error log and returns false instead ...
PoCs for CVE-CVE-2026-19598
CVE-2026-19598-PoC
General
Python
0
DeadExpl0it
2026-08-19