THREAT OPS › Threat News › 100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in Pods WordPress Plugin
100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in Pods WordPress Plugin
<p>On August 10th, 2026, we received a submission for an Unauthenticated Privilege Escalation vulnerability in <a href="https://wordpress.org/plugins/pods/" rel="noopener" target="_blank">Pods</a>, a WordPress plugin with more than 100,000 active installations. This vulnerability allows unauthenticated attackers to escalate their privileges to administrator and perform various administrator action
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- dd648f7d75a7e7a46d7d82c57b085613md5
- d2de85470fb8bc914ee4f18ea34d49dbmd5
- CVE-2026-19598cve
- https://wordpress.org/plugins/pods/url
- https://www.cve.org/CVERecord?id=CVE-2026-19598url
- 3.3.9.1ipv4
- 3.2.8.3ipv4
- 3.1.4.2ipv4
- 3.0.10.4ipv4
- 2.9.19.4ipv4
- 2.8.23.4ipv4
- 3.1.4.1ipv4
- 3.2.8.2ipv4
- 2.8.23.3ipv4
- 2.9.19.3ipv4
- 3.0.10.3ipv4
- www.gravatar.comdomain