CVE-2026-70376: Pluck-CMS Pluck CMS

Critical severity, CVSS 9.6. EPSS: 0.2% chance of exploitation in the next 30 days.

Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.

Affected products

  • Pluck-CMS Pluck CMS: up to and including 4.7.21

Published 2026-08-05. Last modified 2026-08-28.