CVE-2025-46099
In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.
- Affected products
- Pluck Cms
- Pluck-cms Pluck
- = 4.7.20
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 0.5% (39th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2025-07-23
CVE-2025-46099 at NVD
1 known exploit for CVE-2025-46099
Proof-of-concept code and exploit modules indexed by Sploitus