CVE-2026-76573: Pods <= 3.3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'not_found' Shortcode Attribute
Published Sep 5, 2026
·Updated
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'notfound' Shortcode Attribute in all versions up to, and including, 3.3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
1 affected component
WordPress Pods – Custom Content Types and Fields<=3.3.9.1
Event History
Sep 5, 2026
CVE Published
via MITRE·08:27 AM
Data Sourced
via MITRE·08:27 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which users could exploit this issue?
An attacker needs an authenticated WordPress account with Contributor-level permissions or higher.
2
When would injected script run?
The stored script executes when a user accesses a page containing the attacker-injected content.