The Pods plugin for WordPress, which allows users to create custom content types and fields, has a security vulnerability in all versions up to 3.0.10 (excluding versions 2.7.31.2, 2.8.23.2, and 2.9.19.2). This vulnerability is caused by a feature that allows for file inclusion through shortcode. This means that attackers with contributor access or higher can create pods and users with default roles.