Pods Updates & Release Notes
28 updates curated from 1 source by the Releasebot Team. Last updated: Aug 31, 2026
- Aug 31, 2026
- Date parsed from source:Aug 31, 2026
- First seen by Releasebot:Aug 31, 2026
3.3.9.2 - August 31st, 2026
Pods ships a major security hardening release across the plugin, tightening display callbacks, form nonce handling, shortcode and block logic, and post status handling. It also restores anonymous form post handling and adds notices for disallowed display callbacks.
This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.
Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.
Security
Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)
Original source - Aug 31, 2026
- Date parsed from source:Aug 31, 2026
- First seen by Releasebot:Aug 31, 2026
3.2.8.4 - August 31st, 2026
Pods ships a major security hardening release that tightens callbacks, form nonce handling, shortcode and block logic, and post status handling while restoring anonymous form posts and adding warnings for disallowed callbacks.
This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.
Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.
Security
Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)
Original source All of your release notes in one feed
Join Releasebot and get updates from Pods Foundation and hundreds of other software products.
- Aug 31, 2026
- Date parsed from source:Aug 31, 2026
- First seen by Releasebot:Aug 31, 2026
3.1.4.3 - August 31st, 2026
Pods releases a major security hardening update that tightens multiple plugin areas, including safer display callbacks, stronger form nonce handling, and improved shortcode and block protections. It also restores anonymous form post handling and backports the fixes across major versions.
This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.
Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.
Security
- Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
- Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
- Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
- Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
- Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)
- Aug 31, 2026
- Date parsed from source:Aug 31, 2026
- First seen by Releasebot:Aug 31, 2026
3.0.10.5 - August 31st, 2026
Pods ships a major security hardening release across the plugin, tightening display callbacks, form nonce handling, shortcode and block logic, and post status handling. It also restores anonymous form posts and adds admin notices for disallowed callbacks.
This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.
Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.
Security
Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)
Original source - Aug 31, 2026
- Date parsed from source:Aug 31, 2026
- First seen by Releasebot:Aug 31, 2026
2.9.19.5 - August 31st, 2026
Pods ships a major security hardening release that tightens callbacks, nonce handling, shortcode and block logic, and post status handling. It also restores anonymous form post handling and adds detection for disallowed display callbacks, with fixes backported across major versions.
This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.
Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.
Security
Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)
Original source Similar to Pods with recent updates:
- Aug 31, 2026
- Date parsed from source:Aug 31, 2026
- First seen by Releasebot:Aug 31, 2026
2.8.23.5 - August 31st, 2026
Pods releases a major security hardening update with backported fixes across supported versions, tightening display callbacks, form nonce handling, shortcode and block logic, and post status handling while restoring anonymous form posts.
This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.
Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.
Security
Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)
Original source - Aug 31, 2026
- Date parsed from source:Aug 31, 2026
- First seen by Releasebot:Aug 31, 2026
2.7.31.4 - August 31st, 2026
Pods ships a major security hardening release that strengthens multiple areas of the plugin, including safer display callbacks, tougher form nonce handling, and improved shortcode and block protections. It also restores anonymous form post handling and expands security notices for risky usage.
This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.
Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.
Security
Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)
Original source - Aug 14, 2026
- Date parsed from source:Aug 14, 2026
- First seen by Releasebot:Aug 15, 2026
3.3.9.1 - August 14th, 2026
Pods ships a major security hardening release with tighter validation, safer data and file handling, stronger access checks, updated third-party JavaScript dependencies, and new control over REST API documentation access. The update is backported across major supported versions.
This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.
Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above.
Security
Further restrictions on error handling and fallbacks. (Nhien Pham @nhienit - GalaxyOne, @thevietronin - GalaxyOne, @sc0ttkclark)
General hardening improvements to how data queries are built and validated. (HaoNH @haoit, @onebitious, @sc0ttkclark)
Additional restrictions on how certain values are processed when displayed. (@sc0ttkclark)
Improved safety when handling previously stored data. (@sc0ttkclark)
Removed a legacy request-handling path that is no longer needed. (HaoNH @haoit, @sc0ttkclark)
Tightened access requirements for certain background requests. (HaoNH @haoit, @sc0ttkclark)
Improved consistency and enforcement of access and validation checks. (Youness HFA from AGBS Pentest Team @YounesHfa, HaoNH @haoit, @onebitious, @sc0ttkclark)
Hardening improvements to file and media handling. (@sc0ttkclark)
Additional safeguards for file and template handling. (@sc0ttkclark)
Improved handling of displayed content. (@sc0ttkclark)
Added extra verification for admin forms and actions. (@sc0ttkclark)
Additional validation for imported content. (@sc0ttkclark)
Improved handling of content based on user permissions. (@sc0ttkclark)
Updated bundled third-party JavaScript dependencies. (@sc0ttkclark)
Added a filter to optionally restrict access to the REST API documentation endpoint, which remains public by default. (@sc0ttkclark)
Additional automated test coverage for the changes in this release. (@sc0ttkclark)
Original source - Aug 14, 2026
- Date parsed from source:Aug 14, 2026
- First seen by Releasebot:Aug 15, 2026
3.2.8.3 - August 14th, 2026
Pods releases a major security hardening update that strengthens error handling, data queries, content display, file and media handling, admin actions, imports, and permission checks across the plugin. It also removes a legacy request path and tightens validation and access controls.
This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.
Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above.
Security
- Further restrictions on error handling and fallbacks. (Nhien Pham @nhienit - GalaxyOne, @thevietronin - GalaxyOne, @sc0ttkclark)
- General hardening improvements to how data queries are built and validated. (HaoNH @haoit, @onebitious, @sc0ttkclark)
- Additional restrictions on how certain values are processed when displayed. (@sc0ttkclark)
- Improved safety when handling previously stored data. (@sc0ttkclark)
- Removed a legacy request-handling path that is no longer needed. (HaoNH @haoit, @sc0ttkclark)
- Tightened access requirements for certain background requests. (HaoNH @haoit, @sc0ttkclark)
- Improved consistency and enforcement of access and validation checks. (Youness HFA from AGBS Pentest Team @YounesHfa, HaoNH @haoit, @onebitious, @sc0ttkclark)
- Hardening improvements to file and media handling. (@sc0ttkclark)
- Additional safeguards for file and template handling. (@sc0ttkclark)
- Improved handling of displayed content. (@sc0ttkclark)
- Added extra verification for admin forms and actions. (@sc0ttkclark)
- Additional validation for imported content. (@sc0ttkclark)
- Improved handling of content based on user permissions. (@sc0ttkclark)
- Aug 14, 2026
- Date parsed from source:Aug 14, 2026
- First seen by Releasebot:Aug 15, 2026
3.1.4.2 - August 14th, 2026
Pods ships a major security hardening release that tightens error handling, data queries, access checks, file and media handling, and validation across admin forms, imports, and displayed content. The update is recommended as soon as possible and has been backported to Pods 2.7 and above.
Security
This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.
Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above.
- Security: Further restrictions on error handling and fallbacks. (Nhien Pham @nhienit - GalaxyOne, @thevietronin - GalaxyOne, @sc0ttkclark)
- Security: General hardening improvements to how data queries are built and validated. (HaoNH @haoit, @onebitious, @sc0ttkclark)
- Security: Additional restrictions on how certain values are processed when displayed. (@sc0ttkclark)
- Security: Improved safety when handling previously stored data. (@sc0ttkclark)
- Security: Removed a legacy request-handling path that is no longer needed. (HaoNH @haoit, @sc0ttkclark)
- Security: Tightened access requirements for certain background requests. (HaoNH @haoit, @sc0ttkclark)
- Security: Improved consistency and enforcement of access and validation checks. (Youness HFA from AGBS Pentest Team @YounesHfa, HaoNH @haoit, @onebitious, @sc0ttkclark)
- Security: Hardening improvements to file and media handling. (@sc0ttkclark)
- Security: Additional safeguards for file and template handling. (@sc0ttkclark)
- Security: Improved handling of displayed content. (@sc0ttkclark)
- Security: Added extra verification for admin forms and actions. (@sc0ttkclark)
- Security: Additional validation for imported content. (@sc0ttkclark)
- Security: Improved handling of content based on user permissions. (@sc0ttkclark)
- Aug 14, 2026
- Date parsed from source:Aug 14, 2026
- First seen by Releasebot:Aug 15, 2026
3.0.10.4 - August 14th, 2026
Pods ships a major security hardening release with stronger validation, tighter access checks, safer data queries, improved file and media handling, and added safeguards across forms, templates, imports, and displayed content. Updates are recommended as soon as possible.
This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.
Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above.
Security
Further restrictions on error handling and fallbacks. (Nhien Pham @nhienit - GalaxyOne, @thevietronin - GalaxyOne, @sc0ttkclark)
General hardening improvements to how data queries are built and validated. (HaoNH @haoit, @onebitious, @sc0ttkclark)
Additional restrictions on how certain values are processed when displayed. (@sc0ttkclark)
Improved safety when handling previously stored data. (@sc0ttkclark)
Removed a legacy request-handling path that is no longer needed. (HaoNH @haoit, @sc0ttkclark)
Tightened access requirements for certain background requests. (HaoNH @haoit, @sc0ttkclark)
Improved consistency and enforcement of access and validation checks. (Youness HFA from AGBS Pentest Team @YounesHfa, HaoNH @haoit, @onebitious, @sc0ttkclark)
Hardening improvements to file and media handling. (@sc0ttkclark)
Additional safeguards for file and template handling. (@sc0ttkclark)
Improved handling of displayed content. (@sc0ttkclark)
Added extra verification for admin forms and actions. (@sc0ttkclark)
Additional validation for imported content. (@sc0ttkclark)
Improved handling of content based on user permissions. (@sc0ttkclark)
Original source - Aug 14, 2026
- Date parsed from source:Aug 14, 2026
- First seen by Releasebot:Aug 15, 2026
2.9.19.4 - August 14th, 2026
Pods releases a major security hardening update across the plugin, tightening error handling, data queries, content display, file and template handling, admin actions, imports, and permission checks. The update is recommended as soon as possible and has been backported across major versions.
This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.
Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above.
Security
Further restrictions on error handling and fallbacks. (Nhien Pham @nhienit - GalaxyOne, @thevietronin - GalaxyOne, @sc0ttkclark)
General hardening improvements to how data queries are built and validated. (HaoNH @haoit, @onebitious, @sc0ttkclark)
Additional restrictions on how certain values are processed when displayed. (@sc0ttkclark)
Improved safety when handling previously stored data. (@sc0ttkclark)
Removed a legacy request-handling path that is no longer needed. (HaoNH @haoit, @sc0ttkclark)
Tightened access requirements for certain background requests. (HaoNH @haoit, @sc0ttkclark)
Improved consistency and enforcement of access and validation checks. (Youness HFA from AGBS Pentest Team @YounesHfa, HaoNH @haoit, @onebitious, @sc0ttkclark)
Hardening improvements to file and media handling. (@sc0ttkclark)
Additional safeguards for file and template handling. (@sc0ttkclark)
Improved handling of displayed content. (@sc0ttkclark)
Added extra verification for admin forms and actions. (@sc0ttkclark)
Additional validation for imported content. (@sc0ttkclark)
Improved handling of content based on user permissions. (@sc0ttkclark)
Original source - Aug 14, 2026
- Date parsed from source:Aug 14, 2026
- First seen by Releasebot:Aug 15, 2026
2.8.23.4 - August 14th, 2026
Pods releases a major security hardening update that tightens error handling, query validation, access checks, file and media handling, and content processing across the plugin. The fixes have also been backported to Pods 2.7 and above.
This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.
Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above.
Security
Further restrictions on error handling and fallbacks. (Nhien Pham @nhienit - GalaxyOne, @thevietronin - GalaxyOne, @sc0ttkclark)
General hardening improvements to how data queries are built and validated. (HaoNH @haoit, @onebitious, @sc0ttkclark)
Additional restrictions on how certain values are processed when displayed. (@sc0ttkclark)
Improved safety when handling previously stored data. (@sc0ttkclark)
Removed a legacy request-handling path that is no longer needed. (HaoNH @haoit, @sc0ttkclark)
Tightened access requirements for certain background requests. (HaoNH @haoit, @sc0ttkclark)
Improved consistency and enforcement of access and validation checks. (Youness HFA from AGBS Pentest Team @YounesHfa, HaoNH @haoit, @onebitious, @sc0ttkclark)
Hardening improvements to file and media handling. (@sc0ttkclark)
Additional safeguards for file and template handling. (@sc0ttkclark)
Improved handling of displayed content. (@sc0ttkclark)
Added extra verification for admin forms and actions. (@sc0ttkclark)
Additional validation for imported content. (@sc0ttkclark)
Improved handling of content based on user permissions. (@sc0ttkclark)
Original source - May 29, 2026
- Date parsed from source:May 29, 2026
- First seen by Releasebot:May 29, 2026
3.3.9 - May 20th, 2026
Pods fixes a security flaw in admin UI forms and patches an XSS vulnerability reported by Patchstack.
Security
Resolve a XSS vulnerability in the Pods UI forms in the admin area. Props to Bonds through Patchstack for responsibly reporting this. (@sc0ttkclark)
Original source - Mar 19, 2026
- Date parsed from source:Mar 19, 2026
- First seen by Releasebot:Mar 20, 2026
3.3.8 - March 19th, 2026
Pods reuses the Repeatable Fields UI for Relationship fields in List View and improves consistency for upcoming File fields. It also fixes repeatable field reordering, Relationship field ordering, PHP header magic tags, and ACF/SCF compatibility.
Feature: Reuse the same UI that Repeatable Fields use for the Relationship fields using "List View" list items. The UI is now consistent and Pods 3.4 will include the same UI treatment for the File fields. (@sc0ttkclark)
Fixed: Resolve issue with reordering repeatable fields and prevent rendering incorrectly when typing in the field which causes focus to be lost. #7498 #7499 (@pdclark, @sc0ttkclark)
Fixed: Resolve problems with reordering Relationship fields using "List View" list items. (@sc0ttkclark)
Fixed: Resolve issue with Migrate PHP component not placing magic tags on the correct separate new line of the file header. (@sc0ttkclark)
Fixed: Prevent conflicts with ACF/SCF when ACF compatibility functions are enabled.
Curated by the Releasebot team
Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.