CVE-2014-7957, CVE-2014-7956
The Pods plugin before version 2.5 contained multiple cross-site request forgery vulnerabilities that allowed attackers to perform unauthorized actions with administrator privileges. These flaws enabled attackers to execute cross-site scripting attacks, delete pods, reset pod data and settings, deactivate pods, remove the admin role, and toggle roles and capabilities features through unprotected requests to wp-admin/admin.php. The vulnerabilities affected various administrative pages including pods-components, pods, pod-settings, and pods-component-roles-and-capabilities sections of the plugin.
Based on public CVE data (MITRE/NVD).