Extension WordPress

Vulnérabilités Pods – Custom Content Types and Fields

Cette page rassemble les failles publiées pour Pods – Custom Content Types and Fields, leurs plages de versions affectées et les correctifs signalés dans la base locale.

16Vulnérabilités
2Critiques
16Avec correctif
10,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Pods – Custom Content Types and Fields

16 fiches

CVE-2026-54191 Élevée · 7,2
Pods – Custom Content Types and Fields

Pods – Custom Content Types and Fields <= 3.3.8 – Unauthenticated Stored Cross-Site Scripting

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-3.3.8

Correctif

3.3.9

Publication

15/06/2026

CVE-2025-1446 Moyenne · 4,4
Pods – Custom Content Types and Fields

Pods – Custom Content Types and Fields <= 3.2.8.1 – Authenticated (Admin+) Stored Cross-Site Scripting

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.8.1 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-3.2.8.1

Correctif

3.2.8.2

Publication

02/03/2025

CVE-2024-11849 Moyenne · 4,4
Pods – Custom Content Types and Fields

Pods – Custom Content Types and Fields <= 3.2.8 – Authenticated (Admin+) Stored Cross-Site Scripting

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-3.2.8

Correctif

3.2.8.1

Publication

16/12/2024

CVE-2024-3956 Moyenne · 5,4
Pods – Custom Content Types and Fields

Pods – Custom Content Types and Fields <= 3.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Pod Form Redirect URL

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pod Form widget in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping…

Versions affectées

*-3.2.1

Correctif

3.2.1.1

Publication

09/05/2024

CVE-2023-6999 Élevée · 8,8
Pods – Custom Content Types and Fields

Pods – Custom Content Types and Fields – Authenticated (Contributor+) Remote Code Execution

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possible…

Versions affectées

[*, 2.7.31), [2.8, 2.8.23.2), [3, 3.0.10.2)

Correctif

2.7.31.2, 2.8.23.2, 2.9.19.2, 3.0.10.2

Publication

28/03/2024

CVE-2023-6965 Moyenne · 4,3
Pods – Custom Content Types and Fields

Pods – Custom Content Types and Fields – Missing Authorization

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This is due to the fact that…

Versions affectées

[*, 2.7.31), [2.8, 2.8.23.2), [3, 3.0.10.2)

Correctif

2.7.31.2, 2.8.23.2, 2.9.19.2, 3.0.10.2

Publication

28/03/2024

CVE-2023-6967 Élevée · 8,8
Pods – Custom Content Types and Fields

Pods – Custom Content Types and Fields – Authenticated (Contributor+) SQL Injection via Shortcode

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2) due to insufficient escaping on…

Versions affectées

[*, 2.7.31), [2.8, 2.8.23.2), [3, 3.0.10.2)

Correctif

2.7.31.2, 2.8.23.2, 2.9.19.2, 3.0.10.2

Publication

28/03/2024

Vulnérabilité Moyenne · 5,5
Pods – Custom Content Types and Fields

Pods – Custom Content Types and Fields <= 2.7.28 – Authenticated (Admin+) Cross-Site Scripting

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.7.28 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-2.7.28

Correctif

2.7.29

Publication

06/08/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités