The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to a security risk known as SQL Injection in versions before 2.5.1.2. This risk occurs when a user-supplied parameter is not properly escaped and the existing SQL query is not properly prepared. This could allow attackers to add extra SQL queries that can be used to access sensitive information stored in the database.