Pods Foundation maintains the Pods plugin, a WordPress extension for managing custom content types and fields, with a focused vulnerability profile centered on web-application input handling. The durable signal in its disclosures involves cross-site request forgery weaknesses, a characteristic concern for WordPress plugins operating within shared administrative contexts. Live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pods Foundation over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23790HIGH Cross-Site Request Forgery (CSRF) vulnerability in Pods Framework Team Pods – Custom Content Types and Fields plugin <= 2.9.10.2 versions. | May 3, 2023 | 8.8 | 27 | NO | NO |
CVE-2025-1446CRITICAL The Pods WordPress plugin before 3.2.8.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | Mar 23, 2025 | 9.8 | 26 | NO | NO |
CVE-2023-6999HIGH The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the excepti | Apr 9, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-6967HIGH The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7 | Apr 9, 2024 | 8.8 | 22 | NO | NO |
CVE-2021-24339MEDIUM The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Me | Jun 21, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-24338MEDIUM The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Si | Jun 21, 2021 | 5.4 | 20 | NO | NO |
CVE-2024-11849MEDIUM The Pods WordPress plugin before 3.2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scrip | Jan 6, 2025 | 6.1 | 19 | NO | NO |
CVE-2014-7957MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote attackers to hijack the authentication of administrators for req | Jan 15, 2015 | 6.8 | 18 | NO | NO |
CVE-2024-9883MEDIUM The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scrip | Nov 5, 2024 | 4.8 | 16 | NO | NO |
CVE-2023-6965MEDIUM The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, | Apr 9, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pods Foundation.
Media articles that mention a CVE ID that affects a product developed by Pods Foundation — matched by CVE ID, not by vendor name.