CVE-2020-29607: Pluck-CMS Pluck
High severity, CVSS 7.2. EPSS: 33.2% chance of exploitation in the next 30 days.
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.
Affected products
- Pluck-CMS Pluck: before 4.7.13 (fixed in 4.7.13)
Published 2020-12-16. Last modified 2026-06-17.