PLUGIN SECURITY
Is Pods safe?
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
What this plugin does
- Slug:
pods - Author: Scott Kingsley Clark
- 100000+ active installs
- 96/100 rating (418 reviews on wordpress.org)
- 5383980 all-time downloads
- On WordPress.org since 2008-10-08
content typescustom fieldscustom post typesCustom Taxonomiespods
Maintenance status
- Latest known version: 3.3.9
- Last updated: 2026-08-14 3:31pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.2+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
17 known CVEs on file for Pods.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-74851 | Pods - Custom Content Types and Fields [pods] < 3.3.9.1 | Improper Control of Generation of Code ('Code Injection') | Unknown | < 3.3.9.1 | 3.3.9.1 | 2026-08-26 | ⚠ update needed |
| CVE-2026-19598 | Pods - Custom Content Types and Fields [pods] < 3.3.9.1 | Incorrect Authorization | Critical 9.8 | < 3.3.9.1 | 3.3.9.1 | 2026-08-15 | ⚠ update needed |
| CVE-2026-54191 | Pods - Custom Content Types and Fields [pods] < 3.3.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.3.9 | 3.3.9 | 2026-06-15 | ✓ fixed in latest |
| CVE-2024-11849 | Pods - Custom Content Types and Fields [pods] < 3.2.8.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.2.8.1 | 3.2.8.1 | 2024-12-16 | ✓ fixed in latest |
| CVE-2024-9883 | Pods - Custom Content Types and Fields [pods] < 3.2.7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 3.2.7.1 | 3.2.7.1 | 2024-10-15 | ✓ fixed in latest |
| CVE-2024-6297 | Pods - Custom Content Types and Fields [pods] < 3.2.2 | Embedded Malicious Code | Critical 10.0 | < 3.2.2 | 3.2.2 | 2024-06-25 | ✓ fixed in latest |
| CVE-2024-3956 | Pods - Custom Content Types and Fields [pods] < 3.2.1.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.2.1.1 | 3.2.1.1 | 2024-05-09 | ✓ fixed in latest |
| CVE-2023-6999 | Pods - Custom Content Types and Fields [pods] < 3.1 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | High 8.8 | < 3.1 | 3.1 | 2024-03-28 | ✓ fixed in latest |
+ 18 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-6965 | Pods - Custom Content Types and Fields [pods] < 3.0.10.2 | Missing Authorization | Medium 4.3 | < 3.1 | 3.1 | 2024-03-28 | ✓ fixed in latest |
| CVE-2023-6967 | Pods - Custom Content Types and Fields [pods] < 3.1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.8 | < 3.1 | 3.1 | 2024-03-28 | ✓ fixed in latest |
| CVE-2023-33999 | Pods - Custom Content Types and Fields [pods] < 2.8.23 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 2.8.23 | 2.8.23 | 2023-07-18 | ✓ fixed in latest |
| CVE-2023-23790 | Pods - Custom Content Types and Fields [pods] < 2.9.11 | Cross-Site Request Forgery (CSRF) | High 7.1 | < 2.9.11 | 2.9.11 | 2023-01-20 | ✓ fixed in latest |
| — | Pods - Custom Content Types and Fields [pods] < 2.7.29 | — | Unknown | < 2.7.29 | 2.7.29 | 2021-08-06 | ✓ fixed in latest |
| CVE-2021-24339 | Pods - Custom Content Types and Fields [pods] < 2.7.27 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.7.27 | 2.7.27 | 2021-01-15 | ✓ fixed in latest |
| CVE-2021-24338 | Pods - Custom Content Types and Fields [pods] < 2.7.27 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.7.27 | 2.7.27 | 2021-01-15 | ✓ fixed in latest |
| — | Pods - Custom Content Types and Fields [pods] < 2.5.1.2 | — | Unknown | < 2.5.1.2 | 2.5.1.2 | 2015-03-16 | ✓ fixed in latest |
| — | Pods - Custom Content Types and Fields [pods] < 2.5.1.2 | — | Unknown | < 2.5.1.2 | 2.5.1.2 | 2015-03-16 | ✓ fixed in latest |
| CVE-2014-7957, CVE-2014-7956 | Pods - Custom Content Types and Fields [pods] < 2.5 | Cross-Site Request Forgery (CSRF) | Unknown | < 2.5 | 2.5 | 2014-10-07 | ✓ fixed in latest |
| CVE-2014-7956 | Pods - Custom Content Types and Fields [pods] < 2.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 2.5 | 2.5 | 2014-10-07 | ✓ fixed in latest |
| — | Pods - Custom Content Types and Fields [pods] < 3.2.8.2 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.8 | < 3.2.8.2 | 3.2.8.2 | 0000-00-00 | ✓ fixed in latest |
| — | Pods - Custom Content Types and Fields [pods] < 2.7.29 | — | Unknown | < 2.7.29 | 2.7.29 | — | ✓ fixed in latest |
| — | Pods - Custom Content Types and Fields [pods] < 2.5.1.2 | — | Unknown | < 2.5.1.2 | 2.5.1.2 | — | ✓ fixed in latest |
| — | Pods 1.4.7 <= 2.5.1.1 - Blind SQL Injection | — | Unknown | < 2.5.1.2 | 2.5.1.2 | — | ✓ fixed in latest |
| — | Pods < 2.7.29 - Multiple Authenticated Stored Cross-Site Scripting (XSS) | — | Unknown | < 2.7.29 | 2.7.29 | — | ✓ fixed in latest |
| CVE-2023-23790 | Pods < 2.9.11 - Pods Deletion via CSRF | — | Unknown | < 2.9.11 | 2.9.11 | — | ✓ fixed in latest |
| CVE-2025-1446 | Pods < 3.2.8.2 - Admin+ SQL Injection | — | Unknown | < 3.2.8.2 | 3.2.8.2 | — | ✓ fixed in latest |
How to fix it
Keep Pods updated — 3.3.9 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Advanced Custom Fields (ACF®) — 2000000+ active installs — 90/100 (1438) — max PHP 8.4
- Custom Post Type UI — 1000000+ active installs — 92/100 (276) — max PHP 8.4
- Meta Box — 500000+ active installs — 96/100 (165) — max PHP 8.4
- Checkout Field Editor (Checkout Manager) for WooCommerce — 400000+ active installs — 98/100 (1056) — max PHP 8.4
- Admin Columns — 100000+ active installs — 98/100 (1651)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.