SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-74851

HIGH · CVSS 7.2 EPSS 0.50%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Pods WordPress plugin prior to version 3.3.9.1 contains a vulnerability that improperly compares display callbacks against a list of blocked functions, enabling users with author roles and higher to execute arbitrary code on the server. This poses a significant risk to sites using the restricted display-callback mode, which is the default for installations with earlier Pods versions. WordPress site administrators, particularly those using the affected plugin, should prioritize updating to the latest version to mitigate this high-severity threat.

CVE
CVE-2026-74851
Severity
HIGH
CVSS
7.2
EPSS
0.50%
WordPress

Original NVD Description

The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked functions, allowing users with the author role and above to execute arbitrary code on the server. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.