A critical privilege-escalation vulnerability, CVE-2026-19598, has been disclosed in the Pods – Custom Content Types and Fields WordPress plugin, affecting all versions up to and including 3.3.9 and putting roughly 100,000 sites at risk. The flaw lies in the plugin’s pods_admin AJAX router, where authorization and validation failures can be mishandled under a JSON compatibility path involving the meta-box-loader parameter, allowing unauthenticated attackers to bypass login, nonce, capability, and method restrictions.
Successful exploitation can let attackers invoke privileged API methods such as save_user, reset arbitrary user passwords, and gain administrator access, leading to full site takeover. The vendor released patched versions 2.8.23.4, 2.9.19.4, 3.0.10.4, 3.1.4.2, 3.2.8.3, and 3.3.9.1, while detection coverage has also begun appearing in the security community through a Nuclei template pull request tracking the issue. Wordfence said firewall protections were deployed for paid users immediately after disclosure, with broader free-user coverage scheduled later.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
A GitHub pull request in the ProjectDiscovery nuclei-templates repository referenced CVE-2026-19598 as an unauthenticated privilege escalation flaw in Pods up to version 3.3.9, with assignment and review workflow activity recorded that day.
The Pods vendor's patch for CVE-2026-19598 was reviewed and approved, and patched version 3.3.9.1 was released. The advisory also lists patched releases across supported branches, including 2.8.23.4, 2.9.19.4, 3.0.10.4, 3.1.4.2, 3.2.8.3, and 3.3.9.1.
Wordfence validated the report for CVE-2026-19598 and disclosed it to the Pods vendor, which acknowledged the issue and began working on a fix. The same day, Wordfence deployed firewall protection for Premium, Care, and Response users.
A security researcher submitted CVE-2026-19598, an unauthenticated privilege escalation vulnerability in the Pods WordPress plugin, through the Wordfence Bug Bounty Program.
CSIRT Italia reported that CVE-2026-19598 in the Pods WordPress plugin is under active exploitation. The unauthenticated flaw can be exploited through crafted requests to admin-ajax.php to create a WordPress administrator account and take control of an affected site.
After the patched Pods releases became available, WordPress.org coordinated force updates for impacted sites to accelerate remediation of CVE-2026-19598.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcemalware.news
Open sourceacn.gov.it
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.