CVE-2026-19598

Published Aug 15, 2026

Last updated 7 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-19598 describes an unauthenticated privilege escalation vulnerability found in the Pods – Custom Content Types and Fields plugin for WordPress, affecting all versions up to and including 3.3.9. The flaw resides within the `pods_admin` AJAX router, where security checks such as method allowlisting, nonce verification, login enforcement, and capability gates are funneled through the `pods_error()` function. Under the JSON meta-box-loader compatibility path, `pods_error()` may only log failures and return false instead of terminating the request, rendering these security controls ineffective. This bypass allows unauthenticated attackers to perform administrative actions, including escalating their privileges to Administrator or overwriting the password of any user account, potentially leading to a complete site takeover.

Description
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON meta-box-loader compatibility path only writes failures to the PHP error log and returns false instead of terminating the request, rendering all guards ineffective. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator or overwrite the password of any user account, including the site owner's, enabling complete site takeover, or perform another administrator action.
Source
security@wordfence.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@wordfence.com
CWE-863

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2026-19598: Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router Critical Vulnerability Alert! WordPress is affected by CVE-2026-19598. Full Vulnerability Details & Analysis at DarkEye: 🔗

    @zoomeye_team

    26 Aug 2026

    3241 Impressions

    16 Retweets

    48 Likes

    23 Bookmarks

    0 Replies

    0 Quotes

  2. 100,000 WordPress Sites Affected by Privilege Escalation #Vulnerability in Pods #WordPress #Plugin #⃣ CVSS Rating: 9.8 (Critical) 🆔 CVE-ID: CVE-2026-19598 🎯 Affected Version(s): Various: ✅ Patched Versions: 2.8.23.4, 2.9.19.4, 3.0.10.4, 3.1.4.2, 3.2.8.3, 3.3.9.1 https:

    @webknitdigital

    23 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. CVE-2026-19598 hits Pods 2.8-3.3.9 (100k+ sites): its AJAX handler logs failed access checks instead of blocking them, so unauthenticated requests get through. CVSS 9.8. Deactivating isn't enough, update or delete. https://t.co/6ZQcH3mOgR #WordPressSecurity #CVE

    @magicwp_io

    21 Aug 2026

    158 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: EGE-GH-bnhF7il ( CVE-2020-14882 ) EGE-GH-seDznkg ( CVE-2026-65400 ) EGE-GH-voHnlXt ( CVE-2026-15748 ) EGE-GH-UkSlg0M ( CVE-2026-19598 ) EGE-GH-IxgnwCb ( CVE-2025-62593 ) ..🧵👇

    @exploitgrid

    19 Aug 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. BREAKING: CVE-2026-19598 hits the Pods WordPress plugin. Its pods_admin AJAX router can log authorization failures without terminating the request, letting unauthenticated callers reach administrator methods. CVSS 9.8 CRITICAL. 100,000+ active installs. https://t.co/f5fwg9PMMr

    @HashgraphOnline

    16 Aug 2026

    474 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. 🚨*CVE* CVE-2026-19598 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3… https://t.co/jarGzNBpoE ----- Traducción: CVE-2026-19598 El … https://t.co/bYts

    @infoflowcloud

    15 Aug 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes