CVE-2026-74851: Pods < 3.3.9.1 - Author+ RCE via Shortcode Display Callback
The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked functions, allowing users with the author role and above to execute arbitrary code on the server. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pods (WordPress plugin)to a version that resolves this vulnerability.Fixed in 3.3.9.1
Event History
Frequently Asked Questions
Which sites are affected by the configuration requirement?
Only sites using Pods' restricted display-callback mode are affected. This mode is automatically enabled by default when the installation's first Pods version predates 3.1.
What level of access does an attacker need?
An attacker needs a WordPress account with the author role or higher. With that access on an affected site, they can execute arbitrary code on the server.
How can I determine whether my site is exposed?
Check whether the site is running a Pods version earlier than 3.3.9.1 and whether restricted display-callback mode is enabled. Installation history is also relevant, because that mode is the automatic default for installations first using Pods before version 3.1.