Extension WordPress
Vulnérabilités Pods – Custom Content Types and Fields
Cette page rassemble les failles publiées pour Pods – Custom Content Types and Fields, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Pods – Custom Content Types and Fields
16 fiches
Pods – Custom Content Types and Fields <= 3.3.8 – Unauthenticated Stored Cross-Site Scripting
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-3.3.8
3.3.9
15/06/2026
Pods – Custom Content Types and Fields <= 3.2.8.1 – Authenticated (Admin+) Stored Cross-Site Scripting
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.8.1 due to insufficient input sanitization and output escaping. This makes…
*-3.2.8.1
3.2.8.2
02/03/2025
Pods – Custom Content Types and Fields <= 3.2.8 – Authenticated (Admin+) Stored Cross-Site Scripting
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes…
*-3.2.8
3.2.8.1
16/12/2024
Pods <= 3.2.7 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping. This makes…
*-3.2.7
3.2.7.1
15/10/2024
Several WordPress.org Plugins <= Various Versions – Injected Backdoor
Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to…
3.2.3
3.2.4
24/06/2024
Pods – Custom Content Types and Fields <= 3.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Pod Form Redirect URL
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pod Form widget in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping…
*-3.2.1
3.2.1.1
09/05/2024
Pods – Custom Content Types and Fields – Authenticated (Contributor+) Remote Code Execution
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possible…
[*, 2.7.31), [2.8, 2.8.23.2), [3, 3.0.10.2)
2.7.31.2, 2.8.23.2, 2.9.19.2, 3.0.10.2
28/03/2024
Pods – Custom Content Types and Fields – Missing Authorization
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This is due to the fact that…
[*, 2.7.31), [2.8, 2.8.23.2), [3, 3.0.10.2)
2.7.31.2, 2.8.23.2, 2.9.19.2, 3.0.10.2
28/03/2024
Pods – Custom Content Types and Fields – Authenticated (Contributor+) SQL Injection via Shortcode
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2) due to insufficient escaping on…
[*, 2.7.31), [2.8, 2.8.23.2), [3, 3.0.10.2)
2.7.31.2, 2.8.23.2, 2.9.19.2, 3.0.10.2
28/03/2024
Pods <= 2.9.10.2 – Cross-Site Request Forgery
The Pods plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10.2. This is due to missing or incorrect nonce validation when deleting pods. This makes it possible for unauthenticated attackers to…
*-2.9.10.2
2.9.11
20/01/2023
Pods – Custom Content Types and Fields <= 2.7.28 – Authenticated (Admin+) Cross-Site Scripting
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.7.28 due to insufficient input sanitization and output escaping. This makes it…
*-2.7.28
2.7.29
06/08/2021
Pods <= 2.7.26 – Authenticated Stored Cross-Site Scripting via Menu Label field
The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Menu Label' field parameter.
2.4.4.2-2.7.26
2.7.27
15/01/2021
Pods 2.4.4.1 – 2.7.26 – Authenticated Stored Cross-Site Scripting
The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Singular Label' field parameter.
[2.4.4.1, 2.7.27)
2.7.27
15/01/2021
Pods – Custom Content Types and Fields < 2.5.1.2 – SQL Injection
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions before 2.5.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
[*, 2.5.1.2)
2.5.1.2
16/03/2015
Pods <= 2.4.3 – Multiple Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the toggled parameter in a…
*-2.4.3
2.5
12/01/2015
Pods <= 2.4.3 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Pods plugin before 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter in an edit action in the pods page to wp-admin/admin.php.
*-2.4.3
2.5
12/01/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.