CVE-2026-74853CWE-552

CVE-2026-74853

Medium · published September 4, 2026

CVSS v3.1
6.8
EPSS
0%
Percentile
14.3
In the wild
Unconfirmed
What it is

The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.

The record
Technical detail
CVSS v3.1
6.8 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00234 · 14.3th percentile
Weakness
CWE-552 · Files or Directories Accessible to External Parties
Published
2026-09-04T11:17Z
References (1)
EPSS history
Timeline
  • 05 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 04 SEP 06:00Z
    Pods < 3.3.9.2 - Author+ Arbitrary File Read via Shortcode Display Callback
    cvelistv5