The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This is due to the fact that the plugin allows the use of a file inclusion feature via shortcode. This makes it possible for authenticated attackers, with contributor access or higher, to create pods and users (with default role).
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 22 Jan 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Podsfoundation
Podsfoundation pods |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:podsfoundation:pods:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Podsfoundation
Podsfoundation pods |

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-02T08:50:06.714Z
Reserved: 2023-12-19T21:16:40.415Z
Link: CVE-2023-6965

Updated: 2024-08-02T08:50:06.714Z

Status : Analyzed
Published: 2024-04-09T19:15:13.273
Modified: 2025-01-22T17:38:52.513
Link: CVE-2023-6965

No data.

No data.