100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in Pods WordPress Plugin
VULNsource · WRD
On August 10th, 2026, we received a submission for an Unauthenticated Privilege Escalation vulnerability in Pods, a WordPress plugin with more than 100,000 active installations. This vulnerability allows unauthenticated attackers to escalate their privileges to administrator and perform various administrator actions, such as overwriting the password of any user account, including the site owner's, resulting in complete site takeover.
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected