CVE-2026-19598_Pods WordPress Plugin Privilege Escalation Vulnerability
Release Date: 15th August 2026
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that operate WordPress websites using the Pods – Custom Content Types and Fields plugin. This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-19598 is a critical privilege escalation vulnerability in the Pods WordPress plugin, located in its admin-ajax router. The router fails to properly enforce authorization on certain administrative actions, allowing an attacker who holds even a low-privileged account, such as a self-registered subscriber on a site that permits open registration, to escalate that account to administrator level.
This vulnerability is already known to be exploited in the wild, and CERTVU treats it as an active threat rather than a theoretical one. If high privileges are gained, an attacker can take full control of the affected website.
What are the systems affected?
The following version(s) are affected:
Pods 3.3 - 3.3.9, 3.1 - 3.1.4.1, 3.2 - 3.2.8.2, 3.0 - 3.0.10.3, 2.9 - 2.9.19.3, and 2.8 - 2.8.23.3 - (Affected)
Pods 3.3.9.1 and later (and the corresponding patched point release on older branches) - (Not affected, patched)
Sites running an older Pods branch should upgrade to the latest 3.3.x release where possible, rather than only to the patched point release on their existing branch, since ongoing support is strongest on the current branch.
What does this mean?
This vulnerability is already being exploited in the wild and requires only a low-privileged account to trigger.
Step 1 - Obtain a Low-Privileged Account
An attacker registers or otherwise obtains a low-privileged WordPress account, such as a subscriber, on a site running Pods.
Step 2 - Escalate via the Admin-Ajax Router
The attacker sends a request to the Pods admin-ajax router that the plugin fails to properly authorize, elevating the account to administrator level.
Attack Vectors
- Any WordPress site running an affected Pods version that permits user registration, even at the lowest privilege level.
- Direct requests to the Pods admin-ajax router from an authenticated but low-privileged session.
Potential Impact
- Escalate a low-privileged account to administrator level.
- Take full control of the affected WordPress website once administrator privileges are obtained.
Indicators of Compromise (IOCs)
This vulnerability is already known to be exploited in the wild. CERTVU draws attention to the following indicators, while noting that absence of these does not rule out compromise:
- Newly registered low-privileged (e.g. subscriber) accounts that shortly afterwards hold administrator capabilities.
- Unexpected requests to the Pods admin-ajax router in server access logs, particularly from accounts that should not hold administrative rights.
- New administrator accounts, plugin installations, or theme edits that no known staff member performed.
Mitigation process?
CERTVU recommends the following:
-
Update Pods immediately
Upgrade to Pods 3.3.9.1 or later without delay, given confirmed active exploitation. -
Restrict or review open user registration
Where user registration is not required, disable it under Settings > General; where it is required, review who is registering and consider adding manual approval or CAPTCHA controls. -
Audit WordPress user accounts
Review all user accounts for unexpected administrator privileges, particularly any granted to accounts originally created as subscribers. -
Audit the estate for the affected product
Identify every WordPress site in the organisation running Pods and confirm each has been upgraded to 3.3.9.1 or the corresponding patched release. -
Conduct a compromise assessment
Given confirmed active exploitation, review server and application logs for the indicators of compromise above and engage incident response support where compromise is suspected.
For further detail, see Patchstack: WordPress Pods Plugin Unauthenticated Privilege Escalation Vulnerability.
Reference
- https://patchstack.com/database/wordpress/plugin/pods/vulnerability/wordpress-pods-plugin-3-3-9-unauthenticated-privilege-escalation-vulnerability
- https://www.cve.org/CVERecord?id=CVE-2026-19598
- Download advisory (English): CVE-2026-19598_Pods WordPress Plugin Privilege Escalation Vulnerability