pods-framework/pods is vulnerable to Privilege Escalation
98
Critical Risk
The pods_admin AJAX router funnels its method allowlist, nonce check, login enforcement, and capability gate through pods_error(). On the JSON meta-box-loader compatibility path, pods_error() only logs the failure and returns false instead of terminating the request, so those guards never stop execution. An unauthenticated attacker can invoke administrator methods, escalate to an Administrator account, or overwrite any user's password and take over the site. The fix enforces access checks so failed authorization cannot continue past pods_error().
You are affected if you are using a version that falls within the vulnerable range.
pods-framework/pods is vulnerable to Privilege Escalation in versions 3.3.0 - 3.3.9, 3.2.0 - 3.2.8.2, 3.1.0 - 3.1.4.1, 3.0 - 3.0.10.3, 2.9.0 - 2.9.19.3 and 2.8 - 2.8.23.3.
Upgrade the Pods - Custom Content Types and Fields library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant