CyberRota Analysis
AI-GeneratedThe Pods WordPress plugin prior to version 3.3.9.1 contains a vulnerability that improperly compares display callbacks against a list of blocked functions, enabling users with author roles and higher to execute arbitrary code on the server. This poses a significant risk to sites using the restricted display-callback mode, which is the default for installations with earlier Pods versions. WordPress site administrators, particularly those using the affected plugin, should prioritize updating to the latest version to mitigate this high-severity threat.
Original NVD Description
The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked functions, allowing users with the author role and above to execute arbitrary code on the server. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.