Today we have released security patches across every major version starting at Pods 2.7+. If you are running any version of Pods, we strongly recommend updating as soon as possible. We are working with security teams and hosts to get people updated to reduce the length of overall impact for people’s sites.
Affected versions: Pods 2.0+
Patched versions available: Pods 2.7+
Following work from the Pods 3.3.9.1 security release this month, additional security vulnerabilities were responsibly disclosed. We were again able to proactively discover additional issues that could also be targeted for resolution to cover more ground.
We want to extend our sincere thanks to the security researchers who responsibly disclosed these issues and worked with us throughout the process. These fixes would not have been as thorough without the responsible disclosure and collaboration of the following security researchers:
- Jakub Herman
- Wordfence PRISM – Wordfence
Additional thanks go out to everyone involved in bringing older WP/PHP versions to WordPress Playgrounds which gave us the ability to test older versions which only ran on older versions of WordPress.
Pods 3.3.9.2 – Changelog
- Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
- Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
- Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM – Wordfence, @sc0ttkclark)
- Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
- Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)
The backported releases (2.7.x through 3.2.x) include everything in the changelog above.
Patched Releases
| Version | Patched Release | Minimum WP (unchanged) |
|---|---|---|
| Pods 3.3 / 3.3.x | Pods 3.3.9.2 (zip) | WP 6.3+ |
| Pods 3.2 / 3.2.x | Pods 3.2.8.4 (zip) | WP 6.0+ |
| Pods 3.1 / 3.1.x | Pods 3.1.4.3 (zip) | WP 6.0+ |
| Pods 3.0 / 3.0.x | Pods 3.0.10.5 (zip) | WP 6.0+ |
| Pods 2.9 / 2.9.x | Pods 2.9.19.5 (zip) | WP 5.7+ |
| Pods 2.8 / 2.8.x | Pods 2.8.23.5 (zip) | WP 5.5+ |
| Pods 2.7 / 2.7.x | Pods 2.7.31.4 (zip) | WP 4.5+ |
How to Update
From the WordPress Admin
Go to Dashboard > Updates and update Pods if an update is available.
Manual Install
Go to Dashboard > Plugins > Add Plugin > Upload Plugin and provide the corresponding patched plugin ZIPs from the above release list for your chosen version.
Via WP-CLI
wp plugin update pods
Reporting Security Issues
If you believe you have found a security vulnerability, please do not post this information to the public.
Responsible Disclosure Options
- Preferred: Submit a new official Security Advisory via GitHub
- Send an email to
securityat our domainpods.io - Contact Scott Kingsley Clark directly at sc0ttkclark on the Pods Slack
- Work with a WP security vulnerability vendor like WPScan
We will review the vulnerability report and determine the best course of action as quickly as possible. Our goal is to reply within 48 hours.