The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This is due to the fact that the plugin allows the use of a file inclusion feature via shortcode. This makes it possible for authenticated attackers, with contributor access or higher, to create pods and users (with default role).
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Pods - Custom Content Types and Fields - Missing Authorization |
Wed, 22 Jan 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Podsfoundation
Podsfoundation pods |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:podsfoundation:pods:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Podsfoundation
Podsfoundation pods |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:21:00.980Z
Reserved: 2023-12-19T21:16:40.415Z
Link: CVE-2023-6965
Updated: 2024-08-02T08:50:06.714Z
Status : Modified
Published: 2024-04-09T19:15:13.273
Modified: 2026-04-08T19:19:03.297
Link: CVE-2023-6965
No data.
OpenCVE Enrichment
No data.