On August 10th, 2026, we received a submission for an Unauthenticated Privilege Escalation vulnerability in Pods, a WordPress plugin with more than 100,000 active installations. This vulnerability allows unauthenticated attackers to escalate their privileges to administrator and perform various administrator actions, such as overwriting the password of any user account, including the site owner’s, resulting in complete site takeover.
Props to Nhien Pham (nhienit) who discovered and responsibly reported this vulnerability through the Wordfence Bug Bounty Program. This researcher earned a bounty of $3,900.00 for this discovery. Our mission is to secure WordPress through defense in depth, which is why
Click here to continue reading this article.
