Impact
An unauthenticated Cross‑Site Scripting flaw exists in all WordPress Pods plugin releases up to and including version 3.3.8. The vulnerability allows an attacker to inject and execute arbitrary JavaScript in a user’s browser when they view content governed by the Pods framework. The CVE description does not explicitly list downstream effects, but typical XSS consequences such as session hijacking, data theft, or defacement are inferred from the nature of the flaw.
Affected Systems
The affected product is the Pods Framework:Pods WordPress plugin version 3.3.8 and all earlier releases. No other plugins or product variants were identified as vulnerable in the CNA data.
Risk and Exploitability
The flaw carries a CVSS score of 7.1, indicating high severity for a client‑side vulnerability. The EPSS score is below 1 %, suggesting a low exploitation probability at the time of assessment, and the vulnerability is not listed in the CISA KEV catalog. Because the attack does not require authentication and can be triggered by manipulating user‑editable content, any attacker with internet access to the target site could potentially exploit it via a crafted request or page view. Although the current exploitation likelihood is low, the severity of the client‑side impact warrants timely remediation.
OpenCVE Enrichment