CVE

CVE-2014-7956 — Pods - Custom Content Types and Fields [pods] < 2.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2014-7957, CVE-2014-7956 Pods - Custom Content Types and Fields [pods] < 2.5 Cross-Site Request Forgery (CSRF) Unknown < 2.5 2.5 2014-10-07

CVE-2014-7957, CVE-2014-7956

The Pods plugin before version 2.5 contained multiple cross-site request forgery vulnerabilities that allowed attackers to perform unauthorized actions with administrator privileges. These flaws enabled attackers to execute cross-site scripting attacks, delete pods, reset pod data and settings, deactivate pods, remove the admin role, and toggle roles and capabilities features through unprotected requests to wp-admin/admin.php. The vulnerabilities affected various administrative pages including pods-components, pods, pod-settings, and pods-component-roles-and-capabilities sections of the plugin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.