The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This is due to the fact that the plugin allows the use of a file inclusion feature via shortcode. This makes it possible for authenticated attackers, with contributor access or higher, to create pods and users (with default role).
References
Configurations
Configuration 1 (hide)
|
History
22 Jan 2025, 17:38
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-862 | |
First Time |
Podsfoundation pods
Podsfoundation |
|
CPE | cpe:2.3:a:podsfoundation:pods:*:*:*:*:*:wordpress:*:* | |
References | () https://plugins.trac.wordpress.org/browser/pods/trunk/classes/PodsView.php#L750 - Product | |
References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3039486%40pods%2Ftrunk&old=3039467%40pods%2Ftrunk&sfp_email=&sfph_mail= - Product | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/c5d330cd-ad1f-451e-bf41-39cfeb296cf0?source=cve - Third Party Advisory |
21 Nov 2024, 08:44
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://plugins.trac.wordpress.org/browser/pods/trunk/classes/PodsView.php#L750 - | |
References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3039486%40pods%2Ftrunk&old=3039467%40pods%2Ftrunk&sfp_email=&sfph_mail= - | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/c5d330cd-ad1f-451e-bf41-39cfeb296cf0?source=cve - |
09 Apr 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-09 19:15
Updated : 2025-01-22 17:38
NVD link : CVE-2023-6965
Mitre link : CVE-2023-6965
CVE.ORG link : CVE-2023-6965
JSON object : View
Products Affected
podsfoundation
- pods
CWE
CWE-862
Missing Authorization