PSA - Major security issue with the PODS plugin - CVE-2026-19598

As an agency with several hundred sites, we see vulnerabilities pop up all the time, and update them in a timely manner. We use automatic plugin updaters through Flywheel and WP Engine to do this, and generally there is no issue.

Today was different. We have the PODS plugin on about 80 of our sites, and at least 70 of them had fake administrator users added. The vulnerability patch came out on Friday and most of our sites were updated by Saturday / Sunday.

Needless to say, we've had to scramble big time to roll back sites and clean them up, removing all these users and running scans. If you use PODS, I suggest you update it as soon as you can.

This is outlined here: CVE-2026-19598

I figured people in this sub might appreciate the heads up, if they aren't already aware of this!

reddit.com
u/KuntStink — 2 days ago

A few months ago I upgraded from a 4 monitor setup to this, 49" Samsung Odyssey G9 OLED on the bottom and a 34" Samsung Odyssey G5 up top.

Desk is a Flexispot Standing desk E7
Chair is Flexispot C7 Pro Max (I don't love it tbh)

I've got a 5.1 surround hooked up too.

u/KuntStink — 4 months ago

A few months ago I upgraded from a 4 monitor setup to this, 49" Samsung Odyssey G9 OLED on the bottom and a 34" Samsung Odyssey G5 up top.

Desk is a Flexispot Standing desk E7
Chair is Flexispot C7 Pro Max (I don't love it tbh)

I've got a 5.1 surround hooked up too.

u/KuntStink — 4 months ago