CVE-2026-70376: Pluck-CMS Pluck CMS
Critical severity, CVSS 9.6. EPSS: 0.2% chance of exploitation in the next 30 days.
Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.
Affected products
- Pluck-CMS Pluck CMS: up to and including 4.7.21
Published 2026-08-05. Last modified 2026-08-28.