Unrated severityNVD Advisory· Published Jul 23, 2025· Updated Jul 23, 2025
CVE-2025-46099
CVE-2025-46099
Description
In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.
Affected products
2- Pluck/Pluck CMSdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.