The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possible for authenticated attackers, with contributor level access or higher, to execute code on the server.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Jan 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Podsfoundation
Podsfoundation pods |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:podsfoundation:pods:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Podsfoundation
Podsfoundation pods |

Status: PUBLISHED
Assigner: Wordfence
Published: 2024-04-09T18:59:26.244Z
Updated: 2024-08-08T19:46:34.642Z
Reserved: 2023-12-20T14:35:26.617Z
Link: CVE-2023-6999

Updated: 2024-08-02T08:50:06.858Z

Status : Analyzed
Published: 2024-04-09T19:15:13.820
Modified: 2025-01-22T17:34:19.660
Link: CVE-2023-6999

No data.