Panda Pods Repeater Field
Panda Pods Repeater Field has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for Panda Pods Repeater Field has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Panda Pods Repeater Field is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2022-4306Panda Pods Repeater Field <= 1.5.3 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

Panda Pods Repeater Field
Author
Coding Panda
Panda Pods Repeater Field is a plugin for the Pods Framework. It is more than a repeater field: it is a quick way to set up a relational database and present the data on the same page. It takes advantage of Pods table storage, so you don’t need to worry about the posts and postmeta tables expanding dramatically and slowing down page loading. This plugin is compatible with Pods Framework 2.8 or later and has been updated for WordPress 7.0 and Pods 3.3.9. To download Pods Framework, please visit https://pods.io/. After each update, please clear the cache to make sure the CSS and JS are updated. Usually, Ctrl + F5 will do the trick. Introduction
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C