The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possible for authenticated attackers, with contributor level access or higher, to execute code on the server.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 22 Jan 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Podsfoundation
Podsfoundation pods |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:podsfoundation:pods:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Podsfoundation
Podsfoundation pods |

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-08T19:46:34.642Z
Reserved: 2023-12-20T14:35:26.617Z
Link: CVE-2023-6999

Updated: 2024-08-02T08:50:06.858Z

Status : Analyzed
Published: 2024-04-09T19:15:13.820
Modified: 2025-01-22T17:34:19.660
Link: CVE-2023-6999

No data.

No data.