CVE-2026-19598: Critical Pods Plugin Flaw Lets Attackers Reset Admin Passwords
A WordPress site administrator’s password could be changed by an attacker without ever logging in. A critical vulnerability in the popular Pods plugin allowed an unauthenticated outsider to bypass several layers of security checks...