MEDIUM
sc0ttkclark
CVE published 2026-09-05
CVE-2026-76573
CVE-2026-76573 is a Stored Cross-Site Scripting vulnerability in the Pods – Custom Content Types and Fields plugin for WordPress. Authenticated attackers with contributor-level access can inject web scripts via the 'not_found' Shortcode Attribute, affecting all versions up to 3.3.9.1. Defenders managing WordPress sites should assess exposure and prioritize updates to prevent exploitation, focusing on veri [truncated]