CVE-2026-74851
Pods < 3.3.9.1 - Author+ RCE via Shortcode Display Callback
CVSS Score
7.2
EPSS Score
0.2%
EPSS Percentile
11th
The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked functions, allowing users with the author role and above to execute arbitrary code on the server. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.
| Vendor | unknown |
| Product | pods |
| Published | Aug 26, 2026 |
| Last Updated | Aug 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown pods
Be the first to know when new high vulnerabilities affecting unknown pods are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Pods
3.1.0 < 3.3.9.1
References
Credits
Tyler Chin WPScan