CVE-2026-19598Disclosure

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON meta-box-loader compatibility path only writes failures to the PHP error log and returns false instead of terminating the request, rendering all guards ineffective. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator or overwrite the password of any user account, including the site owner's, enabling complete site takeover, or perform another administrator action.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 27 mentions across 10 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 23 signals
  • Disclosure: 11 classified signals
  • Peaked 6d ago at 5 mentions (2026-08-21); latest day: 1
  • 27 total mentions across 10 days

Deep dive

Activity timeline27 mentions / 10d
01345Mentions · 2026-08-15: 2Mentions · 2026-08-16: 3Mentions · 2026-08-19: 2Mentions · 2026-08-21: 5Mentions · 2026-08-24: 4Mentions · 2026-08-25: 3Mentions · 2026-08-26: 2Mentions · 2026-08-27: 4Mentions · 2026-08-31: 1Mentions · 2026-09-01: 1PoC Mentioned / Linked · 2026-08-19: 1PoC Mentioned / Linked · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-25: 2PoC Mentioned / Linked · 2026-08-27: 1Exploit Tool / Code · 2026-08-19: 1Exploit Tool / Code · 2026-08-21: 1Exploit Tool / Code · 2026-08-25: 2Active Exploitation · 2026-08-21: 2Active Exploitation · 2026-08-24: 1Active Exploitation · 2026-08-26: 1Active Exploitation · 2026-08-27: 1Patch / Workaround · 2026-08-16: 2Patch / Workaround · 2026-08-21: 4Patch / Workaround · 2026-08-24: 3Patch / Workaround · 2026-08-27: 2Patch / Workaround · 2026-09-01: 1Technical Details · 2026-08-15: 2Technical Details · 2026-08-16: 3Technical Details · 2026-08-21: 5Technical Details · 2026-08-24: 4Technical Details · 2026-08-25: 2Technical Details · 2026-08-26: 2Technical Details · 2026-08-27: 3Technical Details · 2026-08-31: 1Technical Details · 2026-09-01: 108-1508-1608-1908-2108-2408-2508-2608-2708-3109-01
Signal classification6 categories
Disclosure
1140.7%
Patch
622.2%
Active Exploitation
414.8%
PoC
311.1%
General
27.4%
Exploit
13.7%
Referenced assets27 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-152
Disclosure2
2026-08-163
Disclosure2Patch1
2026-08-192
General1PoC1
2026-08-215
Active Exploitation1Disclosure1Exploit1Patch2
2026-08-244
Active Exploitation1Disclosure2Patch1
2026-08-253
General1PoC2
2026-08-262
Active Exploitation1Disclosure1
2026-08-274
Active Exploitation1Disclosure2Patch1
2026-08-311
Disclosure1
2026-09-011
Patch1
Full discourse20 posts
  • absholi7ly@absholi7ly
    PoC

    #PoC Pods Unauthenticated Privilege Escalation CVE-2026-19598 https://github.com/absholi7ly/PoC-Pods-Unauthenticated-Privilege-Escalation #WordPress #Pods https://t.co/bDNS9BUwJv

    Post summary

    The tweet shares a GitHub link to a Proof‑of‑Concept for CVE‑2026‑19598, detailing an unauthenticated privilege escalation in WordPress Pods, with no evidence of active exploitation or patches mentioned.

    13201387910.6K
    308 followersView on X
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-19598: Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router Critical Vulnerability Alert! WordPress is affected by CVE-2026-19598. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-19598 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-19598" Search Dork: app="WordPress" Exposure: 7.7m instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJXb3JkUHJlc3Mi&t=all&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260826 #Infosec #CyberSecurity #ZoomEye #DarkEye 🚀 ZoomEye continues to expand its AI ecosystem. Today we're introducing WebMCP support, enabling compatible AI agents to discover and invoke ZoomEye tools directly from the website. Explore our AI ecosystem: 1⃣ WebMCP 2⃣ MCP Server →(http://github.com/zoomeye-ai/mcp…) 3⃣ AI Skills →(http://ai.trusttools.cn/skills/zoomeye…) Building an AI-native cybersecurity platform. #Infosec #CyberSecurity #ZoomEye #DarkEye

    Post summary

    The tweet announces CVE‑2026‑19598, highlighting a privilege escalation flaw in WordPress Pods and linking to a detailed analysis, but offers no patch, exploit, or evidence of active exploitation.

    121061305.3K
    12.7K followersView on X
  • ThreatWire@ThreatWire_
    Patch

    🚨 CRITICAL: CVE-2026-19598 (CVSS 9.8) affects the Pods WordPress plugin, putting 100,000+ sites at risk. An unauthenticated attacker can bypass authorization checks and reset the password of any WordPress account, including the site administrator, enabling complete site takeover. Affected versions: Pods ≤ 3.3.9. 🔴 Update immediately and review administrator accounts for suspicious changes. 🔗 https://www.wordfence.com/threat-intel/vulnerabilities/id/3628032a-3121-45a7-8a78-cfcd8ba6af2f #WordPress #Pods #CVE #AccountTakeover #CyberSecurity #Infosec

    Post summary

    The tweet announces the critical CVE-2026-19598 affecting Pods WordPress plugin and urges users to apply the patch immediately to prevent unauthorized account takeover.

    02021162.9K
    1.6K followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-19598 Vendor: WordPress Product: WordPress plugin Pods (sc0ttkclark) – Custom Content Types and Fields Description: The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON meta-box-loader compatibility path only writes failures to the PHP error log and returns false instead of terminating the request, rendering all guards ineffective. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator or overwrite the password of any user account, including the site owner's, enabling complete site takeover, or perform another administrator action. Link: https://github.com/ksotaria1337/cve-2026-19598 #dbugs_vuln

    Post summary

    This post announces a publicly available PoC/exploit for CVE‑2026‑19598 affecting the WordPress Pods plugin, providing a GitHub link to the code, but does not indicate active exploitation, patch availability, or false‑positive claims.

    0501261.1K
    3.6K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    CVE-2026-19598 (CVSS 9.8) in the Pods WordPress plugin enables complete site takeover. Wordfence is blocking attacks in the wild. Update now. #Pods #CVE202619598 #WordPress #PrivilegeEscalation #SiteTakeover #WebSecurity http://securityonline.info/cve-2026-19598-pods-site-takeover/

    Post summary

    CVE‑2026‑19598 is actively exploited against Pods WordPress sites, leading to full site takeover; immediate patching is advised.

    030140888
    13.0K followersView on X
  • HOL@HashgraphOnline
    Disclosure

    BREAKING: CVE-2026-19598 hits the Pods WordPress plugin. Its pods_admin AJAX router can log authorization failures without terminating the request, letting unauthenticated callers reach administrator methods. CVSS 9.8 CRITICAL. 100,000+ active installs. https://t.co/f5fwg9PMMr

    Post summary

    A critical WordPress Pods plugin vulnerability (CVE‑2026‑19598) allowing unauthenticated callers to reach administrator methods via the pods_admin AJAX router has been announced.

    1101501.9K
    19.2K followersView on X
  • yousukezan@yousukezan
    Disclosure

    WordPressプラグイン「Pods」で、未認証の攻撃者が管理者権限を取得できる重大な脆弱性CVE-2026-19598が公開された。Wordfenceは実際の攻撃を確認しており、24時間で1万7302件を遮断したという。 問題はpods_admin AJAXルーターにあり、ログイン状態、nonce、権限などの検査で呼ばれるpods_error()が、特定のJSON互換処理では実行を停止せずfalseを返す。攻撃者は細工したJSONリクエストで各検査を通過させ、管理用メソッドを呼び出せる。Wordfenceによると、これを悪用して任意ユーザーのパスワードを書き換え、管理者アカウントを乗っ取れる。影響するのはPods 3.3.9以前で、修正版は3.3.9.1のほか、3.2.8.3、3.1.4.2、3.0.10.4、2.9.19.4、2.8.23.4として提供された。http://WordPress.org経由の強制更新も実施された。 https://securityonline.info/cve-2026-19598-pods-site-takeover/

    Post summary

    CVE-2026-19598 is a critical vulnerability in the WordPress Pods plugin that allows unauthenticated attackers to take over administrator accounts; active exploitation has been reported by Wordfence, and multiple patched releases are available.

    0201031.6K
    15.0K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🔴 WordPress'te kritik Pods açığı: 100 bin+ site risk altında! WordPress'in "Pods – Custom Content Types and Fields" eklentisinde CVSS 9.8 seviyesinde kritik bir yetki yükseltme açığı (CVE-2026-19598) tespit edildi. Saldırganlar, kimlik doğrulaması gerektirmeden, yetkilendirme kontrollerini aşarak yönetici hesabının parolasını değiştirebiliyor ve siteyi tamamen ele geçirebiliyor. Açık, 3.3.9 ve önceki sürümleri etkiliyor. 🔒 Güncel sürüm: 3.3.9.1 Pods kullanan WordPress sitelerinin sürümlerini acilen kontrol etmesi gerekli.

    Post summary

    A critical privilege‑ escalation vulnerability (CVE-2026-19598) with CVSS 9.8 was discovered in Pods plugin versions 3.3.9 and earlier, allowing attackers to change admin passwords without authentication; upgrade to 3.3.9.1 is urgently recommended.

    00082454
    2.4K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 WordPress'in Pods eklentisindeki CVE-2026-19598 (Unauthenticated Privilege Escalation) açığı için PoC yayınlandı. https://github.com/absholi7ly/PoC-Pods-Unauthenticated-Privilege-Escalation

    Post summary

    A proof‑of‑concept for CVE‑2026‑19598 (unauthenticated privilege escalation) has been published on GitHub, but there is no information about patches or active exploitation.

    00023472
    2.4K followersView on X
  • MagicWP@magicwp_io
    Patch

    CVE-2026-19598 hits Pods 2.8-3.3.9 (100k+ sites): its AJAX handler logs failed access checks instead of blocking them, so unauthenticated requests get through. CVSS 9.8. Deactivating isn't enough, update or delete. https://magicwp.io/blog/pods-plugin-privilege-escalation-cve-2026-19598 #WordPressSecurity #CVE

    Post summary

    The post announces CVE‑2026‑19598, a high‑severity flaw in the Pods plugin that permits unauthenticated access via mishandled AJAX requests, and urges users to update or delete the plugin.

    00040204
    15 followersView on X
  • HOL@HashgraphOnline
    Patch

    Affected: Pods through 3.3.9 Current fixed target: 3.3.9.1 Impact: promote an account to Administrator or overwrite a user password, including the site owner. Update now: wp plugin update pods https://hol.org/blog/cve-2026-19598-pods-wordpress-unauth-admin-takeover

    Post summary

    CVE‑2026‑19598 allows unauthenticated privilege escalation in the Pods WordPress plugin; updating to the fixed version 3.3.9.1 immediately mitigates the risk.

    00040303
    19.2K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    Wordfence found CVE-2026-19598, a critical unauthenticated flaw in the Pods WordPress plugin (100,000+ installs) letting attackers reset any password, including the admin's. #PodsPlugin #CVE202619598 #WordPress #Wordfence #PrivilegeEscalation https://meterpreter.org/pods-wordpress-cve-2026-19598-privilege-escalation/

    Post summary

    Wordfence identified a critical unauthenticated flaw in the Pods WordPress plugin that allows password resets, with a PoC link provided, but no evidence of active exploitation or available patch.

    00011463
    12.9K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-19598 - critical 🚨 Pods &lt;= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX Router &gt; The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Priv... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-19598 @pdnuclei #Nu...

    Post summary

    The tweet announces CVE‑2026‑19598, a critical unauthenticated privilege escalation flaw in Pods plugin versions up to 3.3.9, affecting the pods_admin AJAX router. No PoC, exploit tool, or active exploitation information is provided.

    00020409
    1.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    CVE-2026-19598 (CVSS 9.8): Unauthenticated privilege escalation in the Pods WordPress plugin lets any anonymous attacker overwrite admin passwords and take over sites. 100,000+ installs affected. Key findings: - The pods_admin AJAX router (wp-admin/admin-ajax.php, action=pods_admin) runs every access guard through pods_error(), which under the JSON+meta-box-loader path only logs the failure and returns false instead of halting the request. Because admin_ajax() discards that return value, all guards fall through silently. - An unauthenticated attacker sends a POST to the AJAX endpoint with the Accept: application/json header and meta-box-loader=1, then specifies method=save_user with a target user ID and a new password. The PodsAPI::save_user() method applies no additional auth checks before calling WordPress core user-write functions, enabling full account takeover. - Beyond password overwriting, the bypass exposes the entire pods_admin router: other reachable methods can write PHP to disk or delete arbitrary files, all without authentication. - Patched versions: 3.3.9.1, 3.2.8.3, 3.1.4.2, 3.0.10.4, 2.9.19.4, 2.8.23.4. http://WordPress.org is pushing a forced update, but verify your version now. Hunt your WAF and server logs for unauthenticated POST requests to admin-ajax.php with action=pods_admin and meta-box-loader=1. On affected hosts, audit recent wp_users password-change timestamps and wp_usermeta for unexpected admin role grants. #DFIR_Radar

    Post summary

    CVE-2026-19598 allows unauthenticated attackers to take over WordPress sites via the Pods plugin; patched versions are available and updates are urged.

    10001257
    1.9K followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-GH-UkSlg0M [CRITICAL/PoC] Linked: CVE-2026-19598 CVE-2026-19598 🔗 https://exploitgrid.net/exploits/ceb4f91e-39b8-4de5-90e2-ed4455dcaa9a

    Post summary

    The post announces a PoC for CVE-2026-19598, linking to an exploit grid page that implies available exploitation code, with no mention of active attacks, patches, or debunking.

    1001040
    35 followersView on X
  • iototsecnews@iototsecnews
    Patch

    WordPress Pods プラグインの脆弱性 CVE-2026-19598 が FIX:Web サイトを完全奪取の恐れ https://iototsecnews.jp/2026/08/24/critical-wordpress-pods-flaw-lets-unauthenticated-attackers-gain-admin-access/ WordPress 用プラグイン Pods – Custom Content Types and Fields において、検証失敗時に処理を停止しない欠陥が存在します。権限のない第三者による、特権 API へのアクセス/特権アカウントの認証情報上書き/サイトの不正な制御といった被害が生じる恐れがあります。この脆弱性 CVE-2026-19598 への対策として、修正済みバージョンへの即時更新が必要とされます。あわせて、不正なユーザー変更の点検/ログの確認/パスワードの更新といった対応の実施が求められます。 #CVE202619598 #Pods #Vulnerability #WordPress

    Post summary

    The article highlights a critical flaw (CVE‑2026‑19598) in the WordPress Pods plugin that could let attackers gain full admin control, and urges immediate patching and log checks.

    0001090
    511 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: EGE-GH-bnhF7il ( CVE-2020-14882 ) EGE-GH-seDznkg ( CVE-2026-65400 ) EGE-GH-voHnlXt ( CVE-2026-15748 ) EGE-GH-UkSlg0M ( CVE-2026-19598 ) EGE-GH-IxgnwCb ( CVE-2025-62593 ) ..🧵👇

    Post summary

    The post enumerates several CVEs as critical exploits disclosed today but offers no additional technical or operational details.

    1000056
    35 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    Vulns in WordPress plugins and themes. CVE-2026-82222, CVSS 10 - https://secalerts.co/vulnerability/CVE-2026-82222 CVE-2026-76581 - https://secalerts.co/vulnerability/CVE-2026-76581 CVE-2026-18431 - https://secalerts.co/vulnerability/CVE-2026-18431 CVE-2026-19632 - https://secalerts.co/vulnerability/CVE-2026-19632 CVE-2026-19598 - https://secalerts.co/vulnerability/CVE-2026-19598 #ciso #cio #cto #msp #mssp https://t.co/ILSfPKqogV

    Post summary

    The tweet announces several newly disclosed WordPress plugin/theme vulnerabilities, providing their CVE IDs and a CVSS 10 score for one, while linking to external resources for additional details.

    00000166
    885 followersView on X
  • Hephaestvs@Vulcanux_
    Active Exploitation

    csirt_it: ‼️ #Exploited: rilevato lo sfruttamento attivo in rete della CVE-2026-19598 relativa a #Pods, plugin per #Wordpress Rischio: 🔴 ⚠️ Ove non provveduto, si raccomanda l’aggiornamento tempestivo del software interessato https://x.com/csirt_it/status/2090819678687949278

    Post summary

    CVE‑2026‑19598, affecting the Pods WordPress plugin, is actively being exploited in the wild; users are urged to update the plugin promptly.

    0000048
    632 followersView on X
  • TokyoBlackHatNews@TYOBlackHatNews
    Disclosure

    CVE-2026-19598: Podsプラグインに深刻な脆弱性、攻撃者が管理者パスワードをリセット可能に https://blackhatnews.tokyo/archives/134047

    Post summary

    The article announces a critical vulnerability in the Pods plugin that allows attackers to reset administrator passwords, but provides no PoC, exploit, or patch details.

    0000038
    34 followersView on X

Explore more