What the vulnerability does
01Description
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possible for authenticated attackers, with contributor level access or higher, to execute code on the server.
Explanation of Vulnerability in Simple Terms
02Summary
Pods – Custom Content Types and Fields before version 2.7.31 contains an improper input validation vulnerability that allows authenticated users with low privileges to read sensitive data, modify site content, or disrupt service. The vulnerability exists in how the plugin processes user-supplied input without adequate sanitization. An attacker with a standard user account can exploit this remotely without additional user interaction.
What an attacker can do
03Attacker Capabilities
Read sensitive data, modify content, or disrupt the site's availability.
Potential impact on your site
04Site Impact
User data and site content can be compromised; service availability may be affected.
Conditions required to exploit
05Prerequisites
Attacker needs a low-privilege user account (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
April 9, 2024
CVE published
April 8, 2026
Record updated