CVE-2026-74853
Last modified
CVE-2026-74853 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Pods | >= 3.1.0, < 3.3.9.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-74853?
How severe is CVE-2026-74853?
How do I fix CVE-2026-74853?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-74843A vulnerability was determined in Wavlink WN531P3 and WN535M…10
- CVE-2026-74845Official Document Management System developed by 2100 Techno…8.8
- CVE-2026-74848Inconsistent Interpretation of HTTP Requests ('HTTP Request/…7.5
- CVE-2026-74849Zohocorp ManageEngine ADSelfService Plus versions before bui…9.8
- CVE-2026-7485Incorrect authorization in frozen BI aggregations in Checkmk…2.3
- CVE-2026-74851The Pods WordPress plugin before 3.3.9.1 does not correctly…7.2
- CVE-2026-74858A vulnerability has been found in jae-jae fetcher-mcp up to …6.3
- CVE-2026-74859The shell theme installer in gnome-tweaks extracts user-supp…6.8
- CVE-2026-7486Improper neutralization of special elements used in an SQL c…9.8
- CVE-2026-74860A flaw was found in libxml2 with Python bindings enabled. A …8.5
- CVE-2026-74866@fastify/busboy is a multipart form-data parser for Node.js.…5.8
- CVE-2026-74867SiYuan versions before 3.7.4 contain a cross-site request fo…4.2
Are you affected by CVE-2026-74853?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
