Title: Reset Password vulnerability
Last modified: August 31, 2026

---

# Reset Password vulnerability

 *  Resolved [raoulunger](https://wordpress.org/support/users/raoulunger/)
 * (@raoulunger)
 * [4 days, 15 hours ago](https://wordpress.org/support/topic/reset-password-vulnerability/)
 * Hi,
 * Pods, together with a number of other plugins, suffers from a serious flaw, that
   allows for hostile password reset request from within the account. I’m sure you’re
   aware of this. The flaw was published on the august 15, here:
   [https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/pods/pods-339-unauthenticated-privilege-escalation-via-authorization-bypass-to-admin-methods-via-pods-admin-ajax-router](https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/pods/pods-339-unauthenticated-privilege-escalation-via-authorization-bypass-to-admin-methods-via-pods-admin-ajax-router)
   Your latest update is from august 14, and from the changelog it is not apparent
   to me if the vulnerability has been patched or not. Could you tell if it has,
   and if not, if and when you’re planning to do so?Cheers!

Viewing 1 replies (of 1 total)

 *  Plugin Author [Scott Kingsley Clark](https://wordpress.org/support/users/sc0ttkclark/)
 * (@sc0ttkclark)
 * [4 days, 13 hours ago](https://wordpress.org/support/topic/reset-password-vulnerability/#post-19007603)
 * Pods 3.3.9.1 patched this issue. You can verify since the Wordfence link shows‘
   Patched versions’ and that one is listed there.

Viewing 1 replies (of 1 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Freset-password-vulnerability%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/pods/assets/icon.svg?rev=3286397)
 * [Pods - Custom Content Types and Fields](https://wordpress.org/plugins/pods/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/pods/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/pods/)
 * [Active Topics](https://wordpress.org/support/plugin/pods/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/pods/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/pods/reviews/)

 * 1 reply
 * 2 participants
 * Last reply from: [Scott Kingsley Clark](https://wordpress.org/support/users/sc0ttkclark/)
 * Last activity: [4 days, 13 hours ago](https://wordpress.org/support/topic/reset-password-vulnerability/#post-19007603)
 * Status: resolved