AI description
CVE-2026-19598 describes an unauthenticated privilege escalation vulnerability found in the Pods – Custom Content Types and Fields plugin for WordPress, affecting all versions up to and including 3.3.9. The flaw resides within the `pods_admin` AJAX router, where security checks such as method allowlisting, nonce verification, login enforcement, and capability gates are funneled through the `pods_error()` function. Under the JSON meta-box-loader compatibility path, `pods_error()` may only log failures and return false instead of terminating the request, rendering these security controls ineffective. This bypass allows unauthenticated attackers to perform administrative actions, including escalating their privileges to Administrator or overwriting the password of any user account, potentially leading to a complete site takeover.
- Description
- The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON meta-box-loader compatibility path only writes failures to the PHP error log and returns false instead of terminating the request, rendering all guards ineffective. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator or overwrite the password of any user account, including the site owner's, enabling complete site takeover, or perform another administrator action.
- Source
- security@wordfence.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@wordfence.com
- CWE-863
- Hype score
- Not currently trending
🚨 CVE-2026-19598: Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router Critical Vulnerability Alert! WordPress is affected by CVE-2026-19598. Full Vulnerability Details & Analysis at DarkEye: 🔗
@zoomeye_team
26 Aug 2026
3241 Impressions
16 Retweets
48 Likes
23 Bookmarks
0 Replies
0 Quotes
100,000 WordPress Sites Affected by Privilege Escalation #Vulnerability in Pods #WordPress #Plugin #⃣ CVSS Rating: 9.8 (Critical) 🆔 CVE-ID: CVE-2026-19598 🎯 Affected Version(s): Various: ✅ Patched Versions: 2.8.23.4, 2.9.19.4, 3.0.10.4, 3.1.4.2, 3.2.8.3, 3.3.9.1 https:
@webknitdigital
23 Aug 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-19598 hits Pods 2.8-3.3.9 (100k+ sites): its AJAX handler logs failed access checks instead of blocking them, so unauthenticated requests get through. CVSS 9.8. Deactivating isn't enough, update or delete. https://t.co/6ZQcH3mOgR #WordPressSecurity #CVE
@magicwp_io
21 Aug 2026
158 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: EGE-GH-bnhF7il ( CVE-2020-14882 ) EGE-GH-seDznkg ( CVE-2026-65400 ) EGE-GH-voHnlXt ( CVE-2026-15748 ) EGE-GH-UkSlg0M ( CVE-2026-19598 ) EGE-GH-IxgnwCb ( CVE-2025-62593 ) ..🧵👇
@exploitgrid
19 Aug 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
BREAKING: CVE-2026-19598 hits the Pods WordPress plugin. Its pods_admin AJAX router can log authorization failures without terminating the request, letting unauthenticated callers reach administrator methods. CVSS 9.8 CRITICAL. 100,000+ active installs. https://t.co/f5fwg9PMMr
@HashgraphOnline
16 Aug 2026
474 Impressions
1 Retweet
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨*CVE* CVE-2026-19598 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3… https://t.co/jarGzNBpoE ----- Traducción: CVE-2026-19598 El … https://t.co/bYts
@infoflowcloud
15 Aug 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes