PT-2026-81957 · WordPress · Pods
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pods versions prior to 3.3.9.1
Description
An issue exists where the software fails to correctly compare a display callback against its list of blocked functions. This allows users with the author role or higher to execute arbitrary code on the server. This issue specifically affects sites using the restricted display-callback mode, which is the default setting for installations where the initial Pods version was older than 3.1.
Recommendations
Update Pods to version 3.3.9.1 or later.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pods