SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-74853

MEDIUM · CVSS 6.8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Pods WordPress plugin prior to version 3.3.9.2 is vulnerable due to insufficient restrictions on display callback functions, enabling users with author roles and above to access arbitrary files on the server, including those outside the web root. This poses a significant risk of unauthorized data exposure, particularly for sites utilizing the restricted display-callback mode, which is the default for older installations. WordPress site administrators, especially those using affected versions of the Pods plugin, should prioritize updating to mitigate this vulnerability.

CVE
CVE-2026-74853
Severity
MEDIUM
CVSS
6.8
EPSS
0.23%
WordPress

Original NVD Description

The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.