CVE · Critical

CVE-2024-6297 — Pods - Custom Content Types and Fields [pods] < 3.2.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-6297 Pods - Custom Content Types and Fields [pods] < 3.2.2 Embedded Malicious Code Critical 10.0 < 3.2.2 3.2.2 2024-06-25

CVE-2024-6297

Malicious PHP scripts have been secretly embedded into several WordPress plugins hosted on WordPress.org. An unauthorized party gained access to the source code of these plugins and inserted malicious code that siphons off database login credentials, creates rogue administrator accounts, and transmits this information back to an external server. Until all affected plugins are updated with security patches, it's advisable to remove them temporarily and conduct a thorough malware sweep on your system.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.