๐Ÿ” CVE Alert

CVE-2026-74851

HIGH 7.2

Pods < 3.3.9.1 - Author+ RCE via Shortcode Display Callback

CVSS Score
7.2
EPSS Score
0.2%
EPSS Percentile
11th

The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked functions, allowing users with the author role and above to execute arbitrary code on the server. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.

Vendor unknown
Product pods
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown pods

Be the first to know when new high vulnerabilities affecting unknown pods are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Pods
3.1.0 < 3.3.9.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/4972f315-3819-4fb9-b56a-a88df992416e/

Credits

Tyler Chin WPScan