Pods < 3.3.9.2 - Author+ Arbitrary File Read via Shortcode Display Callback
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.8epss 0.2%
exploitation probability
0.2%top 85% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Affected products
Unknown · Podspublic PoCs found — 1
cve_referencewpscan.com/vulnerability/f53b628f-c825-4cf5-91bd-13bd9526e90c/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.