CVE-2018-11331: Pluck-CMS Pluck

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess.

Affected products

  • Pluck-CMS Pluck: before 4.7.6 (fixed in 4.7.6)

Published 2018-05-21. Last modified 2026-06-17.