WordPress · Pods · CVE-2026-74851
**Name of the Vulnerable Software and Affected Versions**
Pods versions prior to 3.3.9.1
**Description**
An issue exists where the software fails to correctly compare a display callback against its list of blocked functions. This allows users with the author role or higher to execute arbitrary code on the server. This issue specifically affects sites using the restricted display-callback mode, which is the default setting for installations where the initial Pods version was older than 3.1.
**Recommendations**
Update Pods to version 3.3.9.1 or later.