WordPress Plugin Vulnerabilities

Pods < 3.3.9.2 - Author+ Arbitrary File Read via Shortcode Display Callback

Description

The plugin does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.

Proof of Concept

Affects Plugins

Fixed in 3.3.9.2

References

Classification

Type
FILE DOWNLOAD
OWASP top 10
CWE

Miscellaneous

Original Researcher
Erwan LR (WPScan)
Submitter
Erwan LR (WPScan)
Verified
Yes

Timeline

Publicly Published
2026-09-02 (about 2 days ago)
Added
2026-09-02 (about 1 day ago)
Last Updated
2026-09-02 (about 1 day ago)

Other