• PoC PUBLIC

CVE-2026-19598: privilege escalation in sc0ttkclark Pods – Custom Content Types and Fields

Unauthenticated attackers can gain administrator privileges or overwrite user passwords in the Pods – Custom Content Types and Fields WordPress plugin, enabling full site takeover (CVE-2026-19598). The flaw affects all listed 2.x and 3.x releases up to and including the versions shown below: 2.8–2.8.23.3, 2.9–2.9.19.3, 3.0–3.0.10.3, 3.1–3.1.4.1, 3.2–3.2.8.2, and 3.3–3.3.9. An attacker needs only network access to a site running the vulnerable plugin; no authenticated account is required.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.03521
CWE
CWE-863
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Fix urgently: public exploit code exists and the flaw allows unauthenticated full administrator takeover, so treat internet-facing WordPress sites with this plugin as high risk.

What is CVE-2026-19598?

Unauthenticated attackers can gain administrator privileges or overwrite user passwords in the Pods – Custom Content Types and Fields WordPress plugin, enabling full site takeover (CVE-2026-19598). The flaw affects all listed 2.x and 3.x releases up to and including the versions shown below: 2.8–2.8.23.3, 2.9–2.9.19.3, 3.0–3.0.10.3, 3.1–3.1.4.1, 3.2–3.2.8.2, and 3.3–3.3.9. An attacker needs only network access to a site running the vulnerable plugin; no authenticated account is required.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of sc0ttkclark Pods – Custom Content Types and Fields are affected?

BRANCHAFFECTEDFIXED
2.x2.8 – 2.8.23.3
2.x2.9 – 2.9.19.3
3.x3.0 – 3.0.10.3
3.x3.1 – 3.1.4.1
3.x3.2 – 3.2.8.2
3.x3.3 – 3.3.9

Is CVE-2026-19598 being exploited?

Public exploit code is available.

How to fix CVE-2026-19598

  1. Remove or deactivate the Pods plugin on vulnerable sites until a vendor fix is released.
  2. If removal is not possible, restrict access to the WordPress admin area and plugin endpoints by IP or firewall rules.
  3. Monitor authentication and user-change logs for unexpected admin creations or password resets and rotate affected admin credentials.
  4. Follow the plugin vendor's official guidance and apply updates as soon as a fixed release is published.

Frequently asked questions

Is CVE-2026-19598 being actively exploited?

Public exploit code is available for CVE-2026-19598.

Which Pods – Custom Content Types and Fields versions are affected by CVE-2026-19598?

The vulnerability affects the listed 2.x and 3.x ranges: 2.8–2.8.23.3, 2.9–2.9.19.3, 3.0–3.0.10.3, 3.1–3.1.4.1, 3.2–3.2.8.2, and 3.3–3.3.9.

Is there a patch for CVE-2026-19598?

There is no fixed release available for CVE-2026-19598 as of the provided data; apply mitigations and follow vendor guidance until a patch is published.

Does CVE-2026-19598 require authentication?

No — CVE-2026-19598 can be exploited by unauthenticated attackers against the Pods plugin.

References