The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This is due to the fact that the plugin allows the use of a file inclusion feature via shortcode. This makes it possible for authenticated attackers, with contributor access or higher, to create pods and users (with default role).
Metrics
Affected Vendors & Products
References
History
Wed, 22 Jan 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Podsfoundation
Podsfoundation pods |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:podsfoundation:pods:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Podsfoundation
Podsfoundation pods |

Status: PUBLISHED
Assigner: Wordfence
Published: 2024-04-09T18:59:20.952Z
Updated: 2024-08-02T08:50:06.714Z
Reserved: 2023-12-19T21:16:40.415Z
Link: CVE-2023-6965

Updated: 2024-08-02T08:50:06.714Z

Status : Analyzed
Published: 2024-04-09T19:15:13.273
Modified: 2025-01-22T17:38:52.513
Link: CVE-2023-6965

No data.