{"id":"CVE-2026-70376","published":"2026-08-05T08:16:41.703","lastModified":"2026-08-10T12:17:23.317","description":"Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.","cvssScore":9.6,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","cwes":["CWE-352"],"vendors":[],"products":[],"references":[{"url":"https://github.com/pluck-cms/pluck","tags":[]}],"exploitRefs":[{"url":"https://github.com/pluck-cms/pluck","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw in Pluck CMS's admin panel allows attackers to perform cross-site request forgery (CSRF) attacks by manipulating the Referer header, leading to potential unauthorized actions.","exploitability":"Exploitation is relatively straightforward as it requires an attacker to craft a malicious request with the correct Referer header. The precondition is that the attacker must be able to trick a user into performing an action on the admin panel.","blast_radius":"If exploited, this could result in unauthorized changes to the CMS, potentially leading to data loss, compromise of administrative functions, or other severe consequences.","remediation":"Implement a per-request anti-CSRF token in the admin area, as described in the vendor advisory. Upgrade to the specific version 2.590 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["csrf","cms","web","admin","security"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:03:50.785Z"}}