{"id":19007399,"date":"2026-08-31T11:38:36","date_gmt":"2026-08-31T11:38:36","guid":{"rendered":"https:\/\/wordpress.org\/support\/?post_type=topic&#038;p=19007399"},"modified":"2026-08-31T11:42:41","modified_gmt":"2026-08-31T11:42:41","slug":"reset-password-vulnerability","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/reset-password-vulnerability\/","title":{"rendered":"Reset Password vulnerability"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Hi,<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Pods, together with a number of other plugins, suffers from a serious flaw, that allows for hostile password reset request from within the account. I&#8217;m sure you&#8217;re aware of this. The flaw was published on the august 15, here:<br \/><br \/><a href=\"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/pods\/pods-339-unauthenticated-privilege-escalation-via-authorization-bypass-to-admin-methods-via-pods-admin-ajax-router\">https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/pods\/pods-339-unauthenticated-privilege-escalation-via-authorization-bypass-to-admin-methods-via-pods-admin-ajax-router<\/a><br \/><br \/>Your latest update is from august 14, and from the changelog it is not apparent to me if the vulnerability has been patched or not. Could you tell if it has, and if not, if and when you&#8217;re planning to do so?<br \/><br \/>Cheers!<br \/><\/p>\n","protected":false},"template":"","class_list":["post-19007399","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19007399","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":1,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19007399\/revisions"}],"predecessor-version":[{"id":19007402,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19007399\/revisions\/19007402"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=19007399"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}