DIRAS TAKE
Fix urgently: public exploit code exists and the flaw allows unauthenticated full administrator takeover, so treat internet-facing WordPress sites with this plugin as high risk.
What is CVE-2026-19598?
Unauthenticated attackers can gain administrator privileges or overwrite user passwords in the Pods – Custom Content Types and Fields WordPress plugin, enabling full site takeover (CVE-2026-19598). The flaw affects all listed 2.x and 3.x releases up to and including the versions shown below: 2.8–2.8.23.3, 2.9–2.9.19.3, 3.0–3.0.10.3, 3.1–3.1.4.1, 3.2–3.2.8.2, and 3.3–3.3.9. An attacker needs only network access to a site running the vulnerable plugin; no authenticated account is required.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of sc0ttkclark Pods – Custom Content Types and Fields are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 2.x | 2.8 – 2.8.23.3 | |
| 2.x | 2.9 – 2.9.19.3 | |
| 3.x | 3.0 – 3.0.10.3 | |
| 3.x | 3.1 – 3.1.4.1 | |
| 3.x | 3.2 – 3.2.8.2 | |
| 3.x | 3.3 – 3.3.9 |
Is CVE-2026-19598 being exploited?
Public exploit code is available.
How to fix CVE-2026-19598
- Remove or deactivate the Pods plugin on vulnerable sites until a vendor fix is released.
- If removal is not possible, restrict access to the WordPress admin area and plugin endpoints by IP or firewall rules.
- Monitor authentication and user-change logs for unexpected admin creations or password resets and rotate affected admin credentials.
- Follow the plugin vendor's official guidance and apply updates as soon as a fixed release is published.
Frequently asked questions
Is CVE-2026-19598 being actively exploited?
Public exploit code is available for CVE-2026-19598.
Which Pods – Custom Content Types and Fields versions are affected by CVE-2026-19598?
The vulnerability affects the listed 2.x and 3.x ranges: 2.8–2.8.23.3, 2.9–2.9.19.3, 3.0–3.0.10.3, 3.1–3.1.4.1, 3.2–3.2.8.2, and 3.3–3.3.9.
Is there a patch for CVE-2026-19598?
There is no fixed release available for CVE-2026-19598 as of the provided data; apply mitigations and follow vendor guidance until a patch is published.
Does CVE-2026-19598 require authentication?
No — CVE-2026-19598 can be exploited by unauthenticated attackers against the Pods plugin.
References
- nvd.nist.gov/vuln/detail/CVE-2026-19598
- cve.org/CVERecord?id=CVE-2026-19598
- wordfence.com/threat-intel/vulnerabilities/id/3628032a-3121-45a7-8a78-cfcd8ba6af2f?source=cve
- plugins.trac.wordpress.org/browser/pods/tags/3.3.9/includes/general.php#L400
- All sc0ttkclark CVEs on CVE Radar
- CVEs published in September 2026