Impact
This vulnerability enables users with the author role or higher in WordPress sites that use the Pods plugin before version 3.3.9.1 to run arbitrary server‑side code. The flaw arises from an incorrect comparison that fails to block disallowed callback functions. An attacker who can gain author access can inject a malicious shortcode that triggers the compromised callback, leading to full code execution on the website's server environment.
Affected Systems
WordPress sites that have installed the Pods plugin before 3.3.9.1 and that are operating inside the restricted display‑callback mode, which is automatically enabled for installations whose first Pods version predates 3.1. Files, posts, or pages that contain the vulnerable shortcode are particularly at risk.
Risk and Exploitability
The vulnerability is high severity because it permits remote code execution once the attacker has author privileges. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, but the lack of a public exploit does not diminish the risk. The likely attack vector is a maliciously crafted shortcode that forces execution of the blocked function list, achievable by any user with author or higher roles. Exploitation requires only site access and the ability to create or modify content containing shortcodes.
OpenCVE Enrichment