A critical vulnerability (CVE-2026-19598) in the Pods WordPress plugin allows unauthenticated attackers to escalate privileges, potentially leading to complete site takeover. This flaw has a CVSS score of 9.8 and affects versions 2.8 to 3.3.9 of the plugin, with an estimated 100,000 active installations. The vulnerability enables attackers to overwrite administrator passwords via the pods_admin AJAX router, bypassing several security checks.
There have been confirmed exploitation attempts, including over 17,000 blocked attacks within a day, with no public proof-of-concept available. Users are advised to update to version 3.3.9.1 or the equivalent patched release immediately to mitigate this risk.