<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 18:08:36 +0000</lastBuildDate>
    <item>
      <title>CVE-2023-6999 — Pods - Custom Content Types and Fields - Authenticated (Contributor+) Remote Code Execution</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2023-6999</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; sc0ttkclark Pods – Custom Content Types and Fields, podsfoundation pods&lt;/p&gt;
&lt;p&gt;The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possible for authenticated attackers, with contributor level access or higher, to execute code on the server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; sc0ttkclark Pods – Custom Content Types and Fields, podsfoundation pods&lt;/p&gt;
&lt;p&gt;The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possible for authenticated attackers, with contributor level access or higher, to execute code on the server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2023-6999</guid>
    </item>
  </channel>
</rss>
