The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This is due to the fact that the plugin allows the use of a file inclusion feature via shortcode. This makes it possible for authenticated attackers, with contributor access or higher, to create pods and users (with default role).
History

Wed, 22 Jan 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Podsfoundation
Podsfoundation pods
Weaknesses CWE-862
CPEs cpe:2.3:a:podsfoundation:pods:*:*:*:*:*:wordpress:*:*
Vendors & Products Podsfoundation
Podsfoundation pods

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-04-09T18:59:20.952Z

Updated: 2024-08-02T08:50:06.714Z

Reserved: 2023-12-19T21:16:40.415Z

Link: CVE-2023-6965

cve-icon Vulnrichment

Updated: 2024-08-02T08:50:06.714Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-09T19:15:13.273

Modified: 2025-01-22T17:38:52.513

Link: CVE-2023-6965

cve-icon Redhat

No data.