CVE-2026-19598_Pods WordPress Plugin Privilege Escalation Vulnerability

Release Date: 15th August 2026

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that operate WordPress websites using the Pods – Custom Content Types and Fields plugin. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-19598 is a critical privilege escalation vulnerability in the Pods WordPress plugin, located in its admin-ajax router. The router fails to properly enforce authorization on certain administrative actions, allowing an attacker who holds even a low-privileged account, such as a self-registered subscriber on a site that permits open registration, to escalate that account to administrator level.

This vulnerability is already known to be exploited in the wild, and CERTVU treats it as an active threat rather than a theoretical one. If high privileges are gained, an attacker can take full control of the affected website.

Reference

  1. https://patchstack.com/database/wordpress/plugin/pods/vulnerability/wordpress-pods-plugin-3-3-9-unauthenticated-privilege-escalation-vulnerability
  2. https://www.cve.org/CVERecord?id=CVE-2026-19598