PT-2026-81957 · WordPress · Pods

·

CVE-2026-74851

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pods versions prior to 3.3.9.1
Description An issue exists where the software fails to correctly compare a display callback against its list of blocked functions. This allows users with the author role or higher to execute arbitrary code on the server. This issue specifically affects sites using the restricted display-callback mode, which is the default setting for installations where the initial Pods version was older than 3.1.
Recommendations Update Pods to version 3.3.9.1 or later.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74851

Affected Products

Pods