The Pods – Custom Content Types and Fields plugin for WordPress has a security issue that allows attackers to inject harmful code through the admin settings. This can only be done by someone with administrator-level permissions and above, and it only affects multi-site installations or installations where unfiltered_html is turned off.