CVE-2020-18195: Pluck-CMS Pluck

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via the component " /admin.php?action=page."

Affected products

Published 2021-05-17. Last modified 2026-06-17.