← Back to search

CVE-2026-70376

9.6 CRITICALpublic exploit available

Published 2026-08-05 · Updated 2026-08-10

AI risk analysis

Summary
The flaw in Pluck CMS's admin panel allows attackers to perform cross-site request forgery (CSRF) attacks by manipulating the Referer header, leading to potential unauthorized actions.
Exploitability
Exploitation is relatively straightforward as it requires an attacker to craft a malicious request with the correct Referer header. The precondition is that the attacker must be able to trick a user into performing an action on the admin panel.
Blast radius
If exploited, this could result in unauthorized changes to the CMS, potentially leading to data loss, compromise of administrative functions, or other severe consequences.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Implement a per-request anti-CSRF token in the admin area, as described in the vendor advisory. Upgrade to the specific version 2.590 or later.
csrfcmswebadminsecurity

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Weaknesses

CWE-352

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.