CVE-2020-25287: Pligg Project Pligg

High severity, CVSS 7.2. EPSS: 2.7% chance of exploitation in the next 30 days.

Pligg 2.0.3 allows remote authenticated users to execute arbitrary commands because the template editor can edit any file, as demonstrated by an admin/admin_editor.php the_file=..%2Findex.php&open=Open request.

Affected products

Published 2020-09-13. Last modified 2026-06-17.